节点文献
基于协议转换的安全网关原型系统设计与实现
Design and implementation of security gateway prototype system based on protocol translation
【摘要】 提出了一种IPv4,IPv6混合网络下基于协议转换的安全网关原型系统设计(Hybrid-SG),并基于Linux2.6内核Netfilter框架实现了基本功能。Hybrid-SG在协议转换的基础上跟踪UDP/TCP连接会话,并可实施简单的端到端的安全访问控制策略。实验测试结果表明,Hybrid-SG对端到端数据包传输的时延影响不大,可满足企业组网及安全控制的实际需要。
【Abstract】 This paper described the design of a security gateway based on protocol translation in IPv4-IPv6 hybrid network, and implemented a security gateway prototype system based on Linux 2.6 kernel netfilter framework. The prototype system tracks up-layer UDP/TCP connections based on protocol translation and it performs hybrid end-to-end access control policies. Experimental testing results indicate that it has small latency during end-to-end packet transmission and may satisfy the needs of enterprise networking.
【关键词】 网络地址转换—协议转换;
协议转换;
安全网关;
连接跟踪;
端到端访问控制;
【Key words】 NAT-PT; protocol translation; security gateway; connection tracking; end-to-end access control;
【Key words】 NAT-PT; protocol translation; security gateway; connection tracking; end-to-end access control;
【基金】 江苏省自然科学基金资助项目(BK2005411)
- 【文献出处】 计算机应用 ,Journal of Computer Applications , 编辑部邮箱 ,2007年02期
- 【分类号】TP393.08
- 【被引频次】7
- 【下载频次】200