节点文献

IPv6下基于病毒过滤防火墙的设计与实现

Design and Implementation of IPv6 Transparent Firewall with Virus Filtering

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张玉芳熊忠阳赖苏张科刘君王银辉

【Author】 ZHANG Yu-fang1 XIONG Zhong-yang2,3 LAI Su1 ZHANG Ke1 LIU Jun1 WANG Yin-hui1(Department of Computer Science1,Post-Doctorial Research Station of Electrical Engineering2,Network and Information Management Center3,Chongqing University,Chongqing 400030,China)

【机构】 重庆大学计算机学院重庆大学电气工程博士后流动站重庆大学信息与网络管理中心

【摘要】 包过滤防火墙无法检测出网络病毒,因此对其研究很有必要。设计的防火墙屏蔽了Linux自身的TCP/IP协议栈,重新构建了适合防火墙专用的TCP/IP协议栈,完成了防火墙上TCP协议的连接保持、数据包确认、文件传输等功能。防火墙主要考虑了HTTP协议下的文件过滤,使得内网主机在通过HTTP协议下载文件时自动过滤病毒文件,保证内网主机的安全;防火墙以Linux可加载内核模块形式实现,可以过滤链路层以上的各层;为提高病毒检测速度,提出了将病毒检测软件运行在核心态的方法。实验结果表明:设计的防火墙在性能和功能上都达到了预期目的。

【Abstract】 The existing packet filtering firewall is helpless for the spread of network virus,making a study on the designed of anti-virus firewall is very necessary.This paper designed and realized an experimental anti-virus firewall in IPv6.The firewall was realized in the form of kernel loadable module,and can be used to filter virus above link layer.The special TCP/IP used for firewall is rebuilt because transparent mode firewall cannot be run in the original TCP/IP of Linux.The firewall can get and resolve IPv6 packets and the IPv6 in IPv4 tunnel packet.It can also traverse every extension header until higher protocol layers.The firewall uses open source software to filter the virus in the network and ensures network security.For working in the kernel mode,the detecting speed was improved.The experimental results show that the performance and function of the firewall achieve the desired objectives.

【关键词】 IPv6防火墙透明模式病毒过滤
【Key words】 IPv6FirewallTransparent modeVirus filter
【基金】 教育部留学回国人员启动基金(教外司留[2007]1108-10);中国博士后科学基金(20070420711)资助
  • 【文献出处】 计算机科学 ,Computer Science , 编辑部邮箱 ,2009年04期
  • 【分类号】TP393.08
  • 【被引频次】9
  • 【下载频次】222
节点文献中: 

本文链接的文献网络图示:

本文的引文网络