Welcome to visit《 Journal of Air Force Engineering University 》Official website!

Consultation hotline:029-84786242 RSS EMAIL-ALERT
Design and Implementation of a Firewall IPS Module
DOI:
CSTR:
Author:
Affiliation:

Clc Number:

TP391

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    Two different design schemes about firewall IPS module are brought up. In the first scheme snot-inline technique and the QUEUE action of netfilter are used to achieve dropping of attack data packet. In the second one, IPS about Denial of Service attack is achieved with the benefit of combination of synccokies, the new netfilter fuzzy match, PSD match, U32 match with an improvement on the firewall kernel. After comprehensive comparison, the module is developed according to the second scheme. The experiment shows that the designed module works well in defending main DOS attack.

    Reference
    Related
    Cited by
Get Citation
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:
  • Revised:
  • Adopted:
  • Online: November 17,2015
  • Published:
Article QR Code