论文部分内容阅读
本文介绍了基于专业过滤器的网络管理与安全系统的设计和实现过程,该系统结合了包过滤、用户认证、计费和数据加密等多种技术.由屏蔽路由器、屏蔽主机等实现的包过滤器出于本身的安全、性能和复杂性等考虑,其过滤策略很难改变,用户不能参与管理帐户权限.本系统借鉴了代理服务器中的用户认证功能,使用户可参与管理自己的帐户权限,可有效地防止合法IP地址的非法盗用.同时,由于采用了硬件加速和包过滤技术,可得到较高的吞吐量,可服务的用户数较多.目前,以PC专业过滤器实现的网络管理与安全系统已在西安交通大学等校园网中采用
This article describes the design and implementation of a network-based management and security system based on a professional filter that combines technologies such as packet filtering, user authentication, accounting and data encryption. Due to its own security, performance and complexity considerations, packet filters implemented by shielded routers, masked hosts, etc. have a hard time changing filtering policy and users can not participate in managing account permissions. The system draws on the user authentication function in the proxy server, allowing users to participate in the management of their own account permissions, which can effectively prevent the illegal use of legitimate IP addresses. At the same time, due to the use of hardware acceleration and packet filtering technology, higher throughput can be obtained, can serve more users. At present, the network management and security system realized by the PC professional filter has been adopted in Xi’an Jiaotong University and other campus networks