A dynamic network security system and a control method thereof in a router
where an Intrusion Detection System (IDS) and a Voice over Internet
Protocol Application Level Gateway (VoIP ALG) are integrated, system
including: a VoIP ALG module for acquiring VoIP IP/port information of a
counterpart unit in use for determining whether or not to perform
intrusion detection on a packet received via VoIP signaling with the
counterpart unit; an intrusion detection module for comparing the
received packet with a preset intrusion detection log entry to perform
intrusion detection on the received packet, and based on a result of the
intrusion detection, determining whether or not to allow passage of the
received packet; and an IP/port check module for checking VoIP IP/port
information of the received packet according to the VoIP IP/port
information of the counterpart unit provided from the VoIP ALG module to
determine whether or not to perform the intrusion detection, and
providing result information on the determination whether or not to
perform the intrusion detection to the intrusion detection module.