期刊文献+

内网数据链路层安全通信组件设计与实现

Design and Implementation of Secure Communication Component on Data Link Layer in Intranet
下载PDF
导出
摘要 针对内网嗅探、网络途径主动泄密等威胁,为提高内网通信过程中数据的保密性,设计并实现了一种安全通信组件。组件在Windows系统内核层以网络过滤驱动的形式实现,可嵌入NDIS体系。在终端通信过程中,该组件自动协商会话密钥,对数据链路层数据包执行加解密操作,实现过程对终端用户透明。试验结果显示,该组件能够实现终端保密通信,抵御内网嗅探和防止主动泄密,提高Windows系统的通信安全性,达到预期目的。 To avoid such threats as sniff attack or divulging secrets on purpose through network,and improve the data security in the process of communication in Intranet, the paper designs and implements a kind of component. The component is designed as the form of network filter driver in the kernel level of windows,which can be well embedded in NDIS architecture. In the process of communication between the terminals in Intranet,the components negotiate the session key automatically and use it to encrypt or decrypt the data link layer packets and the entire procedure is transparent to the user. The result of experiment show that the terminals which have loaded the component can communicate each other secretly and prevent the network sniff attack or the inside from divulging secrets on purpose through network, which improves the security of windows as expected.
出处 《现代电子技术》 2008年第17期76-79,共4页 Modern Electronics Technique
关键词 内网安全 数据链路层 密钥管理 Windows内核驱动 NDIS Intranet security data link layer key management Windows kernel driver NDIS
  • 相关文献

参考文献6

  • 1IEEE802.3. IEEE Std 802.3,2000 Edition[S].
  • 2Systems Network Architecture Formats [DB/OL]. IBM document # GA27 - 3136 - 12.
  • 3[美]Russinovich M E,Solomon D A.深入解析Windows操作系统-Microsoft Windows Server 2003/Windows XP/Windows 2000技术内幕[M].4版.潘爱民,译.北京:电子工业出版社,2007.
  • 4武安河.Windows 2000/XP WDM设备驱动程序开发[M].2版.北京:电子工业出版社,2005.
  • 5[英]毛文波.现代密码学理论与实践[M].王继林,译.北京:电子工业出版社,2004.
  • 6Andrew G Mason,Mark J Neweomb.网络安全Ciseo解决方案[M].詹文军,译.北京:电子工业出版社,2002.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部