基于IPv6的分布式智能防火墙系统的设计与实现

    Design and Implementation of Distributed Intelligent Firewall Based on IPv6

    • 摘要: 针对目前IPv6环境下缺乏应用层内容过滤防火墙的现状,设计并实现了一种IPv6分布式智能防火墙原型系统.该系统通过网络层策略规则,可对IPv4和IPv6共有攻击以及IPv6特有攻击进行拦截,通过应用层策略规则,可阻拦非法、反动的网页数据.原型系统的智能性确保整体网络的策略快速主动共享.经实验测试,该原型系统能完成上述功能,并且性能良好.

       

      Abstract: IPv6,as the alternative of IPv4,contains numerous features and improvements that make it attractive from a security perspective,but it is by no means the panacea for security.This paper presents the design and implementation of a distributed intelligent firewall system based on IPv6,which is able to secure the network layer and application layer of IPv6 networking.By the system,the typical attacks coexisting in both IPv4 and IPv6,the emerging IPv6 specific ones such as security threats related to ICMPv6,can be blocked by the rule set of network layer.Similarly,with the rule set of application layer,any illegal or reactionary Web page content in HTML source codes can be totally prevented from sneaking into the Intranet.The initiative drift mechanism ensures the legitimacy and civilization of the Web environment within the whole IPv6 networking.

       

    /

    返回文章
    返回