Beijing Municipality electronical government net is one important part of The capital imformational infrastructure, and join to internet logically. So, it's security is very serious. For having a good information security, Beijing Municipality Office ornanizes some specialists and others to study information technology and information security technical, and want to get information security policy and solutions. The Intrusion Detection Model is important ont part of the solutions.In this paper, a new model of network intrusion detection based on active counterwork response is proposed. It utilizes existing IDS advanced and matured technologies, and imports the active tracing and locating theory. Once some intrusion actions or attempts are found by a detector, apart from local and simple response, the tracing to the stepping stones along the intrusion path based on the SWT technique, and the countermeasures such as remote blocking or remote isolation are used in the network which closes to the attacker. This method prevents hackers from sequent attack, thereby enhances the security of network system greatly. |