节点文献

基于hook的Windows防火墙驱动程序研究与设计

Research and design of Windows firewall driver based on hook

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 鲜继清谭丹陈辉

【Author】 XIAN Ji-qing~1,TAN Dan~2,CHEN Hui~2 (1. College of Automation, Chongqing University of Posts and Telecommunications, Chongqing 400065, China;2. College of Computer Science and Technology, Chongqing University of Posts and Telecommunications, Chongqing 400065, China)

【机构】 重庆邮电学院自动化学院重庆邮电学院计算机科学与技术学院重庆邮电学院计算机科学与技术学院 重庆400065重庆400065重庆400065

【摘要】 在分析介绍Windows2000/XP平台的网络驱动程序的基础上,提出了一种使用NDIShook技术实现防火墙驱动程序的方法。这种方法不同于已有的APIhook技术,它无需重新启动操作系统就能生效,并增强了抵御网络攻击的能力。由于它工作在网络层,可以对所有进出计算机的数据包进行过滤,因此可以更方便有效地保护用户信息安全。同时提出并设计了一个基于共享内存和事件对象的驱动程序通信模型。分析证明该模型可有效提高驱动程序与应用程序通信的效率。

【Abstract】 The network driver of Windows 2000/XP was analyzed, and a scheme of implementing firewall driver using NDIS(Network Driver Interface Specification) hook was presented. Different from API hook, the method could take effect without reboot and strengthen the ability of resisting intrusion. The driver worked on network layer and filtered all data packets through the computer, so it could protect users’ information effectively and conveniently. A driver communication model based on share memory and event object was also provided. The analysis of this model indicates that it can greatly improve the communication efficiency between driver and application.

【关键词】 防火墙NDIS钩子驱动程序共享内存事件对象
【Key words】 firewallNDIS hookdrivershare memoryevent object
【基金】 国家863计划项目(2003AA412030)
  • 【文献出处】 计算机应用 ,Computer Applications , 编辑部邮箱 ,2005年07期
  • 【分类号】TP393.08
  • 【被引频次】10
  • 【下载频次】310
节点文献中: 

本文链接的文献网络图示:

本文的引文网络