基于NDIS中间层驱动的DDoS防火墙的设计  被引量:2

Design of Firewall Against DDo S Attacks Based on NDIS Intermediate Drivers

在线阅读下载全文

作  者:万伟[1] 

机构地区:[1]西南科技大学理学院,四川绵阳621010

出  处:《实验科学与技术》2015年第2期32-35,共4页Experiment Science and Technology

基  金:西南科技大学实验技术研究基金资助项目(13syjs-32)

摘  要:分布式拒绝服务攻击是当前网络上最为严重的攻击手段之一。为了有效防御DDo S攻击,文中讨论一种Windows平台下,基于网络驱动接口规范中间层驱动技术防御DDo S攻击的原理。由于NDIS中间层驱动位于Windows网络组件很低的层次,因此,可以拦截所有的以太网包,具有效率高、拦截准确、系统资源开销小的特点,配合黑白名单、单个IP连接数等策略,几乎让攻击者没有可利用的漏洞。它特别适合用来做大型专业网络的防火墙。The attack by Distributed Denial of service is one of the most grievous ploys in internet at the present time. On the platform of Windows,based on NDIS intermediate drivers a principle of defense is proposed to handle DDos attacks in this paper. Because NDIS intermediate drive is located in the rather low level of Windows network components,it can intercept all Ethernet packets,having such features as being efficient,intercepting precisely and having small expenses of systemic resources. Coordinating with such tactics as black- and- white lists and single IP linkage numbers,almost no loopholes can be taken advantage of by attackers. All of these features can be best applied to make large scale and specialized network firewalls.

关 键 词:网络驱动接口规范 中间层驱动 分布式拒绝服务 防火墙 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象