摘要
在TCP/IP协议的基础上,分别讨论了数据包的封装与分解,IPv6数据包结构和过渡技术,提出了一种准确高效的探测入侵的新技术-协议分析技术,然后详述了协议分析技术在Snort中的应用过程,详细介绍了IPv6解码的过程。结果表明:在Snort中添加IPv6解码模块,使Snort具有了对IPv6数据包的检测能力。
On the basis of TCP/IP protocol,this paper discussed the encapsulation and decomposition of packet,IPv6 packet structure and transition technology,and puts forward a kind of accurate and efficient new technology that detects invasion-protocol analysis technology.and then analyzes the protocol analysis technology applicated in Snort.At last,the decoding process about IPv6 is introduced in detail.The result shows that IPv6 decoding function enables snort to have the detecting capability of IPv6 packets.
出处
《计算机安全》
2011年第3期32-35,共4页
Network & Computer Security