节点文献

基于Netfilter的IPv6防火墙研究

【作者】 高鸿峰

【导师】 傅光轩;

【作者基本信息】 贵州大学 , 计算机技术, 2007, 硕士

【摘要】 随着Internet的迅速发展,当前Internet核心协议——IPv4在面临址资源即将耗尽、端对端连接以及对网络安全等问题,不能适应新的网络应用和Internet的发展。IPv6作为下一代Internet核心仂、议取代IPv4成为必然。同时,IPv6的网络安全问题也摆在人们面前。防火墙作为一种有效的网络安全设备已在IPv4网络得到广泛的应用,但在IPv6环境中针对防火墙应用的还尚待研究。Linux作为一种开放源代码的操作系统,在世界各地有着广泛的应用。Linux内核版本2.4中已采用了Netfilter的防火墙框架,且内核中已支持IPv6协议栈。目前Linux防火墙作为一种包过滤防火墙在IPv4下的应用稳定可靠,在IPv6下的应用尚未得到重视。基于以上分析选择在Linux环境下研究基于Netfilter框架的IPv6防火墙。本文介绍了IPv4与IPv6的比较,详细讨论了IPv6编址方案和IPv6报文格式,网络安全体系结构和网络安全处理过程,防火墙核心技术和体系结构以及Netfilter框架。针对目前缺乏IPv6环境下的高性价比的防火墙的现状,具体论述了基于Netfilter的IPv6防火墙系统总体方案的选择及其实现思路,描述了系统环境的硬件平台的选择和基本环境的裁减、优化,重点讨论了在Linux环境下基于Netfilter框架的IPv6防火墙系统的几个关键功能:包过滤、连线跟踪、状态检测包处理的工作原理和具体实现。

【Abstract】 With the rapid development of Internet, many problems brought by IPv4 have been coming froth: the address resource is using up, current IP protocol is unsuitable to new network application and security is unable to ensure. It’s necessity for IPv6 to replace IPv4. Meanwhile, the security of the next generation network has become the problem demanding prompt solution. Firewall, as a powerful tool in the security of Network, has been widely used in IPv4 Network. However, this powerful tool is seldom used in IPv6 Network.As an open source Operation System, Linux has been widely used on all kinds of platforms. Netfilter framework, which is the middle level of Linux Operation System and Firewall applications, has been integrated into Linux kernel 2.4 .Linux kernel 2.4 has supportted IPv6 protocol stack. Linux firewall is a kind of Packet Filter Firewall of stability and reliability in IPv4 Network, but It’s no use in IPv6 Network.This paper analyzing the essential theory of IPv6 protocol group with comparing the difference of IPv4 and IPv6 protocol, IPv6 Addressing, IPv6 Header Formate, Network Scurity,Firewall and Netfilter.Because of the lack of high efficient firewall based on IPv6,the paper mainly discusses the overall plan of the IPv6 firewall system based on the Netfilter, and describes the choice of hardware platform and the filter ,optimization of basic situation.sepecially focuses on the key functions of IPv6firewall system based on the Netfilte under the circumstances of Linux:Package filter,Connection Track, Package Mangle.

  • 【网络出版投稿人】 贵州大学
  • 【网络出版年期】2007年 05期
  • 【分类号】TP393.08
  • 【被引频次】2
  • 【下载频次】242
节点文献中: 

本文链接的文献网络图示:

本文的引文网络