Intrusion detection is used for detecting and identifying attacks to computer systems, network systems, even more extensive information systems, or detecting the events against security strategies. Intrusion detection collects data from computer system or network and then analyzes them. If any suspected attack behaviors or anomaly events are found, then some certain responses intercepting attacks can be choose to reduce potential loss. There are many products in intrusion detection field by the research on theories and technologies, but under the background of quick development on the whole, the development of kernel technology and reform are still unsatisfied. Especially with the application of some new technologies like high-speed local network and fiber communication, nowadays the 1000M network is pretty common, but the traditional NIDS could only work in 100M network, so the research on intrusion detection in high-speed network is very important and difficult. |