摘要
介绍了基于Linux netfilter/iptables架构实现机制和扩展技术,在此基础上提出扩展匹配选项实现防火墙的入侵检测功能,扩充后的防火墙可以像Snort一样具有入侵检测功能,从而扩展了防火墙的安全控制功能,并且可将Snort规则转化为防火墙规则实现防火墙规则集的扩充。
The implementing way and expanding technic were introduced based on linux netfilter/iptables structure, and based on the foundation, expanding matching option was introduced to get firewall inbreaking and checking of function. Expanded firewall are as same as snort with inbreaking and checking of function, so that firewall safety and cortrol function was expanded, and snort rule was made to become firewall rule to implement expanding firewall.
出处
《计算机工程与设计》
CSCD
北大核心
2005年第8期2223-2225,共3页
Computer Engineering and Design