首页> 外文会议>10th USENIX Security Symposium, Aug 13-17, 2001, Washington, D.C., USA >Transient Addressing for Related Processes: Improved Firewalling by Using IPV6 and Multiple Addresses per Host
【24h】

Transient Addressing for Related Processes: Improved Firewalling by Using IPV6 and Multiple Addresses per Host

机译:相关进程的临时寻址:通过使用IPV6和每个主机多个地址来改进防火墙

获取原文
获取原文并翻译 | 示例

摘要

Traditionally, hosts have tended to assign relatively few network addresses to an interface for extended periods. Encouraged by the new abundance of addressing possibilities provided by IPv6, we propose a new method, called Transient Addressing for Related Processes (TARP), whereby hosts temporarily employ and subsequently discard IPv6 addresses in servicing a client host's network requests. The method provides certain security advantages and neatly finesses some well-known firewall problems caused by dynamic port negotiation used in a variety of application protocols. A prototype implementation exists as a small set of kame/BSD kernel enhancements and allows socket programmers and applications nearly transparent access to TARP addressing's advantages.
机译:传统上,主机倾向于长时间为接口分配相对较少的网络地址。受IPv6提供的新的寻址可能性的鼓舞,我们提出了一种称为“相关过程的临时寻址”(TARP)的新方法,通过该方法,主机可以临时使用并随后丢弃IPv6地址来服务于客户端主机的网络请求。该方法具有一定的安全优势,并且巧妙地解决了由各种应用协议中使用的动态端口协商引起的一些众所周知的防火墙问题。原型实现是对kame / BSD内核的一小部分增强,它允许套接字程序员和应用程序几乎透明地访问TARP寻址的优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号