节点文献
基于divert socket的应用层防火墙
A Divert Socket Based Application Layer Firewall
【摘要】 针对包过滤防火墙和状态检测防火墙的安全控制层次较低、控制能力有限、不能依据数据包内容进行控制的缺点,介绍一种在FreeBSD的IPFW防火墙之上,使用转发套接字建立进程级应用层防火墙的技术。通过这种技术建立的应用层防火墙既保留包过滤防火墙和状态检测防火墙对用户透明的优点,又具有针对特定应用进行访问控制的能力。
【Abstract】 Package-filter firewall and state-check firewall work at network layer,they have very limited control abilities and can not check the content of IP data package.In this paper,we introduce a technology to develop application layer firewall which running as user process.With this technology,we can develop application layer firewall with the advantage of user-transparency,good performance,etc.This technology is based on FreeBSD’s IPFW firewall system and divert socket.
【关键词】 FreeBSD;
IPFW防火墙;
转发套接字;
防火墙;
访问控制;
【Key words】 FreeBSD; IPFW; Divert socket; Firewall; Access control;
【Key words】 FreeBSD; IPFW; Divert socket; Firewall; Access control;
- 【文献出处】 微处理机 ,Microprocessors , 编辑部邮箱 ,2006年05期
- 【分类号】TP393.08
- 【被引频次】1
- 【下载频次】61