摘要
本文描述的动态网络控制技术使用基于TDI层的过滤驱动技术实现,可以完成基于进程、IP地址、端口、用户和协议的多元过滤、检测。通过对注册表、文件系统、IDT表、SSDT表等处进行Hook,进行学习,记录程序正常运行时的状态,建立规则,以此对程序异常行为进行监控,实施防火墙联动。最后使用一个缓冲区溢出攻击实验对系统的执行效果进行了检验。
Implementing with tdi fitler driver technology,this network control system can do filtration and detection based on process information,IP address,port,user and protocol.Hooking windows registry,file system,IDT table and SSDT table,it records behaviors of programs and sets up rules to detect abnormity of system.Besides,it can do firewall linkage and prevents system being attacked again.At last,using an attack based on buffer overflow loophole to test.
出处
《微型电脑应用》
2008年第5期34-35,33,共3页
Microcomputer Applications