An Intrusion(1)System(IDS)is a system that monitors network traffic for suspicious activity and alerts when such activity is discovered While(2)detection and reporting are the primary functions of an IDS,some IDSs are also capable of taking actions when(3)activity or anomalous traffic is detected,including(4)traffic sent from suspicious Internet Protocol(IP)addresses,Any malicious venture or violation is normally reported either to administrator or collected centrally using a(5)information and event management(SIEM)system.A SIEM system integrates outputs from multiple sources and uses alarm filtering techniques to differentiate malicious activity from false alarms.
status
service
security
section
入侵(检测)系统(IDS)是一种监测网络流量以发现可疑活动并在发现此类活动时发出警报的系统,而(异常)检测并报告是IDS的主要功能,一些IDS还能够在检测到(恶意)活动或异常流量时采取行动,包括(存储)从可疑的互联网协议(IP)地址发送的流量,任何恶意冒险或违规行为通常都会报告给管理员,或使用(安全)信息和事件管理(SIEM)系统集中进行收集。SIEM系统集成了来自多个来源的输出,并使用警报过滤技术来区分恶意活动和假警报。