节点文献
开放式包过滤虚拟机的设计
Design of virtual machine of opening packet filter
【摘要】 该系统是针对网络协议测试中错误注入、网络安全检测中过滤机需求而设计.在充分理解Windows网络体系结构中的链路层、网络层、传输层与NDIS驱动接口之间的关系的基础上,利用Hook技术将包捕获驱动挂接在网络层与链路层二者之间.它不仅包含常规的捕获驱动功能,而且实现了ring0与ring3相互调用,用户在应用级直接操作ring0层的数据结构,具有良好的开放性和可扩张性.系统在Windows环境下实现,已在协议测试、安全检测中得到应用.
【Abstract】 The system is designed for faulty injection in protocol test of network and packet filter of IDS. On the basis of understanding their relations, such as link layer, netowrk layer and NDIS driver adapter, the virtual machine is used for filtering the data packet embedded between network layer and link layer using Hook technique. Besides normal functions, it has such capacity that Ring0 and Ring3 can call each other. The system is superior in opening and expand ability, and applications where Ring0’s data structure can be directly read and written.This system has been functioning under the windows system and applied in areas, such as protocol-test, IDS ect.
【Key words】 network architecture; NDIS driver; Hook technique; packet-filter;
- 【文献出处】 安徽工程科技学院学报 ,Journal of Anhui Institute of Mechanical and Electrical Engineering , 编辑部邮箱 ,2002年02期
- 【分类号】TP393.1
- 【被引频次】4
- 【下载频次】51