分布式防火墙环境的边界防御系统
Boundary Defense System Based on DFW
-
摘要: 针对传统边界防火墙在动态防御方面的缺陷,对防火墙和入侵检测系统之间的三种联动技术进行分析比较,提出了一种基于分布式防火墙环境,具备防火墙和入侵检测功能,采用系统嵌入方式的边界防御系统模型。模型利用队列通信机制实现防火墙和入侵检测协同工作,共同检测和防范对系统的入侵行为,并通过安全通信模块与分布式防火墙连接。最后给出了在Linux下的实现。Abstract: Allusion to the limitation of the traditional boundary firewall in dynamic defense, the thesis analyses and compares three interactive technologies between firewall and intrusion-detection system and proposes a boundary defense system model which with the function of firewall and intrusion detection adopts system embedded mode based on the distributed firewall environment. It implements firewall cooperates with intrusion detection by queue communication. Firewall and intrusion detect and defend intrusion to system and connect to distributed firewall by secure communicating module. Finally the thesis expatiates on the realization in Linux.