摘要
从netfilter总体结构入手,分析了netfilter的连线跟踪、包过滤、地址转换、包处理等关键技术。在此基础上,研究了入侵响应策略,提出了基于netfilter的主动响应模型。经测试证明,这种主动响应模型灵活高效,可以极大地增强系统对入侵行为的防御能力。
Netfilter is the framework inside the Linux 2.4.x kernel which enables packet filtering, network address translation (NAT) and other packet mangling. This paper begins with introduction to the framework of netfilter, and some key technology, such as the connection tracking, packet filtering, network address translation, and packet mangling are analyzes in detail. In addition, the strategy of response to intrusion is researched in this paper, and an active response model based on netfilter is given. Through the test proofed, the model could efficiently strengthen the system security.
出处
《电子科技大学学报》
EI
CAS
CSCD
北大核心
2005年第1期94-96,共3页
Journal of University of Electronic Science and Technology of China
基金
国家863计划资助项目(2002AA142040)
关键词
连线跟踪
入侵响应
主动响应
入侵行为重定向
connection tracking
response to intrusion
active response
intrusion redirect