详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
With the popularization of Internet in many fields, more and more application of Internet has been adopted. And we often heard some bad news about hackers and crackers, who had broken into computers and systems again. So the security of network is more important nowadays, and it is becoming a focus of Internet. Why is Internet so frangible? After analyzing many events of network attacks and invalid intrusions, we found that the frangibility of Internet is due to lack of the firewall to protect the network security.
    As you know, Internet nowadays bases on the IPv4 protocol, which has some imperfect. IPv6 will be the necessary developed current in the future, as is the new thought of designing firewall systems. This dissertation put forward a resolvable means of integrating into firewall and IDS to protect network security. That is the design and implement of IPv6 firewall in Linux.
    At the begin of the dissertation, we has discussed the state of security on Internet, analyzed the factors caused frangibility of Internet, and intrude some means used to provide security services for Internet. After that, this dissertation focus on secure network access and designing and implementing the firewall system as follows.
    Firstly, we have summarized some means and methods of firewall implement according to software engineering in detail at Chapter II. It contains collectivity design, demand analysis, system implement, software and hardware situation and the results of system. Then we discussed the principle and develop current of software and hardware.
    Secondly, we discussed the realization principle and concretely process of firewall system. At Chapter III, we suggested some configuration and effective principle such as sniffer, data analyze and transact, database operate and flux statistics, and the principle of transplant to IPv6. According to these theory and principles, we implemented a package filter firewall of IPV6 at Chapter IV.
    In the end, we have tested the IPv6 firewall system at Chapter V , especially test the IPv6 system. According to the results we analyzed the shortage of the system and provided the resolve methods, and prospected the IPv6 firewall technology at Chapter VI.
[1] 北京启明星辰信息技术有限公司.防火墙原理与实用技术.电子工业出版社.2002.1
    [2] 21世纪信息安全研讨会.会议报道.计算机世界.2000.5.15
    [3] 严望佳.21世纪的网络与网络安全.计算机世界.2000.10.30
    [4] Terry William Ogletree. Practical Firewall. 电子工业出版社.2001年
    [5] 刘渊,乐红兵.因特网防火墙技术.机械工业出版社.1998年
    [6] 孙静,曾红卫.网络安全检测与预警.计算机工程.Vol.27 No.7 109-110
    [7] 胡昌振,李贵涛.面向21世纪网络安全与防护.北京希望电子出版社.2000.2
    [8] 杨波,朱秋萍.Web安全技术综述.计算机应用研究.2002.10 1-4
    [9] William R. Cheswick. Firewall and Internet Security. 机械工业出版社.2000年
    [10] 王海霞,赵正军,刘纪平.网络防火墙技术浅析.计算机工程与设计.Vol.23 No.2 14-17
    [11] 路璐,马先立.利用网络入侵检测系统与防火墙的功能结合构建安全网络模型.计算机应用研究.No.10 93-95 2002年
    [12] 蒋建春,冯登国.网络入侵检测原理与技术.国防工业出版社.2001.7
    [13] Rebecca Gurley Bace. 入侵检测.人民邮电出版社,2001.6
    [14] Terry Escamilla. Intrusion Detection. 电子工业出版社.1999.7
    [15] 蒋嶷川,田盛丰.数据挖掘技术在入侵检测系统中的应用.计算机工程.Vol.27 No.4 130-131
    [16] 骆炎民,张全秋,吴金龙.改进地防火墙技术.福建电脑,2002.8
    [17] Silvano Gai.IPV6网络互连与Cisco路由器.机械工业出版社.2000.2
    [19] Stevens W R. TCP/IP illustrated. Vol. 1, 2, 3. Addison-wesley Press, 1998
    [20] S. Deering, R. Hinden,"Internet Protocol, Version 6(Ipv6)Specification", RFC 1883, December 1995
    [21] 谭海平.Linux下IPV4和IPV6的互操作性研究.http://www. china-pub.com 2002-09-29 09:08:26
    [22] R. Braden, Editor. Requirements for Internet Hosts--Communication Layers. RFC1122. 1989-10
    [23] T. Narten, E. Nordmark. Neighbor Discovery for IP Version 6 (IPv6). RFC 2461. 1998-12
    [24] Kent S. Atkinson R. Security architecture for the Internet protol. IETF, Internet RFC:2401 ,November, 1998
    [25] Kent S, Atkinson R. IP authentication header. IETF, Internet RFC; 2402, November 1998
    [26] Kent S, Atkinson R. IP Encapsulating Security Payload(ESP). IETF, Internet RFC; 2402, November 1998
    [27] 李滢,赵杨川.IPV6协议及其发展现状.本溪冶金高等专科学校学报.Vol.4 No.1 4-6
    [28] Danesh A. 邱仲潘译.Linux从入门到精通.电子工业出版社,1999
    [29] 何田.Linux管理员指南.清华大学出版社.1999
    [30] 青松研究室.Linux初学与实作.青岛出版社.1999
    [31] http://tech.sina.com.cn/s/2001-11-14/2139.html
    [32] http://yesky.com/20010717/189277.shtml
    [33] 金勇华,曲俊生.Java网络高级编程.人民邮电出版社.2001年8月
    [34] Eckel B. Java编程思想.Thinking in Java. 机械工业出版社.2000
    [35] 万映辉,张水平等,基于TCP/IP信息哄骗技术的研究与实现.计算机工程.Vol.27 No.3 127-128
    [36] Stevens W R. UNIX环境高级编程.机械工业出版社.1999年
    [37] Baruch R, Schroeter C. Writing Character Device Driver for Linux. 1994
    [38] Welsh. Matt. Linux权威指南.中国电力出版社.2000年3月
    [39] http://www.xfocus.org
    [40] 李碧容.Linux环境下的socket编程 2000.12.09 http://www.china-pub.com/computers/emook/0532/info.htm
    [41] 唐正军,刘代志.网络嗅探器Sniffer软件源代码浅析(1).计算机工程.Vol.27 No.5 165-166
    [42] 唐正军,刘代志.网络嗅探器Sniffer软件源代码浅析(3).计算机工程.Vol.28 No.2 63-65
    [43] Russell P R. Unreliable Guide to Hacking the Linux Kernel. 2000
    [44] McCanne S, Jacobson V. The BSD Packet Filter: A new Architecture for User-level packet Capture. Proceedings of the 1993 Winter USENIX Technical Conference, USENIX, 1993-01
    [45] Denning D. E. An Intrusion-detection Model. IEEE Transactions on Software Engineering, 1987, SE-13(2)
    [46] 严桂兰,刘甲耀.Java在网络多媒体声像设计中的应用.计算机应用.Vol.21 No.6 59-60
    [47] 王东滨,方滨兴等.基于WEB管理的网络监测技术的设计与实现.计算机工程.Vol.28 No.10 203-204
    [48] 易正强,王耀军.基于Proxy的网络计费系统的设计与实现.计算机工程.Vol.27 No.2 166-168
    [49] 吴黎兵,崔建群.基于SNMP协议的校园网计费系统的数据采集.计算机应用.Vol.21
    No.3 81-83
    [50] 红蜻蜓IP地址分配查询工具.冬威软件工作室.http://www.supersoft.com.cn/
    [52] Gilligan R, ThomonS, Bound J, et al. Basic Socket Interface Extensions for IPv6. RFC 2553, 1999-03
    [53] 夏涛,余胜生.开发支持IPV6的应用程序.计算机工程.Vol.27 No.10 51-52
    [54] Stevens W, Thomas M. Advanced Sockets API for IPv6. RFC2292. 1999
    [55] 唐正军,刘代志.网络嗅探器Sniffer软件源代码浅析(2).计算机工程.Vol.28 No.1 11-13
    [56] 袁春阳,柴乔林等.网络入侵检测系统中网络实时监听程序的设计与实现.计算机工程.Vol.28 No.10 150-152
    [57] 黄锦,李家滨.基于防火墙日志信息的入侵检测研究.计算机工程.Vol.27 No.9 115-117
    [58] www.dukejava.com作者:javaduke 2001-05-30 永远的UNIX
    [59] 何杰,夏荣霞.利用Java Swing实现数据库结构化查询界面.计算机应用,Vol.21.No.3 93-94
    [60] Carol McCullough-Dieter.Oracle8实用大全.中国水利水电出版社,1999
    [61] 隋杰,于华.基于JDBC的JavaBuilder4.0数据库应用程序设计.计算机工程.Vol.27 No.12 189-190
    [62] Wutka M.张森译.Java编程技巧.浙江科学技术出版社.西蒙与舒斯特国际出版公司,1999
    [63] R. Gilligan, S. Thomson, J. Bound, W. Stevens. Basic Socket Interface Extensions for IPV6. RFC 2553, March 1999
    [64] J. Postel. RFC 790. 1981-9
    [65] J. Reynolds, J. Postel. RFC 1700. 1994-10
    [66] IPV6羽翼渐丰——新型互联网服务指日可待.互联网周刊.2002.7.13
    [67] Patrick Chan, Rosanna Lee.Java类库手册.北京大学出版社.1996年
    [68] 谢斌,罗勃.Linux网站建设技术指南.机械工业出版社.2000年8月

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700