摘要
网闸是网络安全防护手段之一,传统方法是硬件实现,成本高、控制复杂。本文提出了一种逻辑网闸技术,基于Linux网桥的Ebtables架构,可以在链路层截获数据,并利用逻辑开关实现单向数据通过以及应用层过滤等功能,从而在软件上实现了一个物理隔离网闸的作用。
The gap is one of defense method on security.In the tradition way,the gap is realized by hardware,and the control is complex.Based on Linux bridge frame,a new logic gap based bridge(LGBB)method is proposed,which can capture packet in link layer,realize unidirectional data stream by logical switch,and filter data in application layer.The logical gap fulfills most function of traditional physical gap.
出处
《河南科技大学学报(自然科学版)》
CAS
2008年第5期26-29,共4页
Journal of Henan University of Science And Technology:Natural Science
基金
国家"863"计划基金项目(2006AA01Z406)
关键词
逻辑网闸
网桥
逻辑开关
Logical gap
Bridge
Logical switch