摘要
对基于REDHAT Linux9.0内核防火墙netfilter的原理进行了深入研究,分析了在netfilter架构下防火墙的设计与实现,叙述了Linux的动态地址转换,论述了在Linux下防火墙的设计和开发过程.基于netfilter架构开发了一款包过滤和应用代理的混合型防火墙.针对常见的IP地址欺骗、IP源路由欺骗、ICMP重定向欺骗、IP劫持等网络攻击给予了分析并在过滤管理模块中给出了防御的方法.
In this thesis the athor discusses the netfilter mechanism of REDHAT Linux9.0 kernel, and analyzes how to design and realize the firewall based on netfilter technology, and also describes network address translation in Linux and how a netfilter-based firewall is realized. Common network attacks such as IP spoofing, source route spoofing, ICMP redirect deception and IP Hijack are analyzed and protected by filter manage module.
出处
《甘肃联合大学学报(自然科学版)》
2006年第5期65-69,78,共6页
Journal of Gansu Lianhe University :Natural Sciences