Bro 網絡安全監控器
Bro是一個強大的網絡分析框架,它與ids相比又有很多不同的地方。與通用的網絡傳輸分析工具相比它側重于網絡安全監控和提供一個完整的平臺化工具。
-
Adaptable
Bro's domain-specific scripting language enables site-specific monitoring policies.
-
Efficient
Bro targets high-performance networks and is used operationally at a variety of large sites.
-
Flexible
Bro is not restricted to any particular detection approach and does not rely on traditional signatures.
-
Forensics
Bro comprehensively logs what it sees and provides a high-level archive of a network's activity.
-
In-depth Analysis
Bro comes with analyzers for many protocols, enabling high-level semantic analysis at the application layer.
-
Highly Stateful
Bro keeps extensive application-layer state about the network it monitors.
-
Open Interfaces
Bro interfaces with other applications for real-time exchange of information.
-
Open Source
Bro comes with a BSD license, allowing for free use with virtually no restrictions.