| With the development and popularization of networks, the Intranet security is becoming more and more important, reinforce monitor and control the actions of host computers in Intranet is the key to solving the question. This paper through analysis of packet capture and decoding technique, introduces the host behavior real-time analysis system based on the C/S model, and research several key technologies and functions realization such as network protocol model, network monitoring module, program monitoring module, and so on.This paper discusses the significance of the research papers and the demand analysis of the system, give the general structure of the system, introduces network model and protocol stack of system realization process, detailed descriptions of the TCP/IP layered model of the transmission unit of data format.On the basis of explained the Sniffer operation principle, the paper has expounded the general procedure of designing a Sniffer and the technology and application of monitoring in the switching network, and gives a thorough analysis to monitor network based on the WinPcap, introduces the WinPcap system structure and its main API functions, by calling the library functions to capture all packets of the local network, and perform protocol analyzing and decoding on these packets, so as to achieve the network real-time monitoring.The program monitoring module uses C/S distributed structure, through to research the key technology, design and realization method, puts forward program monitoring module design and realization method, and finally discusses the possibility of data mining in analysis systems.The host behavior real-time analysis system follows a way of active security management and monitor, the system manage and control the Intranet all software and hardware resource, It can monitor and record the behavior of each host user in intranet with the network monitoring and program monitoring combination method, and actively and effectively prevented the inetwork's hidden trouble in Intranet. |