论文部分内容阅读
讨论了基于网络体系结构不同层次的防火墙 ,可以实现不同程度的透明性和访问控制能力。传统的防火墙很多都是基于 Linux操作系统 ,由于 Win-dows在桌面系统中仍占据主导地位 ,主要对 Windows下的防火墙的设计和实现进行分析。首先对处于网络不同层次的防火墙所采用的实现技术和特点进行分析 ,并针对传统的网络层防火墙实现技术难度大 ,应用层防火墙透明性不高和无法实施全面的访问控制的特点 ,采用 L SP技术在网络结构的中间层构筑防火墙 ,以达到技术复杂度和透明度以及功能方面的较好均衡。然后介绍了 LSP技术 ,以及利用 L SP开发防火墙的具体方法。最后阐述了根据 LSP的灵活性嵌入安全控制策略和进行的功能扩展。
Discussed the different levels of the firewall based on network architecture, can achieve different degrees of transparency and access control. Many traditional firewalls are based on the Linux operating system. Since Win-dows still dominates the desktop system, it mainly analyzes the design and implementation of the firewall under Windows. Firstly, the implementation techniques and characteristics of the firewall at different levels of the network are analyzed. In view of the technical difficulty of the traditional network-layer firewall and the low transparency of the application-layer firewall and the inability to implement comprehensive access control, Technology in the middle of the network structure to build a firewall in order to achieve technical complexity and transparency and functional balance. Then introduced the LSP technology, as well as the use of L SP to develop a specific method of firewall. Finally, the flexibility of embedding security control strategy based on LSP and the expansion of functions are described.