检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
作 者:王麒[1]
机构地区:[1]贵州师范大学物理与电子科学学院,贵州贵阳550001
出 处:《计算机安全》2013年第5期34-38,共5页Network & Computer Security
基 金:贵州省科学技术基金项目"基于IPV6的入侵检测技术研究"
摘 要:随着IPv6网络的部署范围加大,IPv6的安全策略的不完善已经越来越制约IPv6网络的发展。虽然一些知名的网络设备制作企业,如CISCO都发布了一些基于IPv6的网络产品,然而它们却没有发布支持IPv6的IPS(入侵防御系统)和IDS(入侵检测系统)设备,此外,现在已经公开的IDS事实标准并不支持IPv6。介绍了一种能应用在IPv6网络环境下多线程结构的IPS系统,并对该系统进行了测试分析。该模型是建立在计算机软件基础上实现的上,并优先应用于IPv6网络。尽管在测试中发现该系统存在一定的局限性,但是该模型还是为将来开发在IPv6环境下的硬件IPS系统进行了研究和探索,并对基本概念进行了定义。The deployment of the IPv6 network becomes to be realized as the necessity of the IPv6 network is enlarged due to the limit of the IPv4 network.However,the security policy about the IPv6 network is not mature as the IPv4 network and it becomes an obstacle in the IPv6 network deployment.Up to date,in the main network equipment provider including CISCO,and etc,the IPv6based firewall is released.However,it nearly does not have the IPv6-based Intrusion Detection System(IDS) and/or Intrusion Prevention System(IPS) equipment.Moreover,in the open source,the snort which is the de facto standard of the IDS system yet does not support IPv6.This paper introduces the implementation of Intrusion Prevention System(IPS) that can be applicable to the IPv6 network and has the multi-thread architecture for the performance improvement.The prototype introduced in this paper is implemented as software base in order to be applied to the IPv6 network preferentially.Although it has a limit to a performance,the prototype can give the basic concepts toward the IPv6-based IPS equipment of the afterward hardware base.
分 类 号:TP393.4[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.195