首页> 外文会议>2017 International Conference on Trends in Electronics and Informatics >An improved Linux firewall using a hybrid frame of netfìlter
【24h】

An improved Linux firewall using a hybrid frame of netfìlter

机译:使用netfìlter混合框架的改进的Linux防火墙

获取原文
获取原文并翻译 | 示例

摘要

With the steady advancement of the network technology present day, network not only brings us a conducive and productive life, and is followed by a collection of network security threats. Due to awareness about the threats the need for security has never been more important that's why it has become extremely important to protect our web servers as well as our web assets. A firewall is main security component that allows and restrict access to specific network and ports. In this research main focus is on designing strong firewall filtering rules so that detection of malicious code will be achieved to the optimal level. The proposed framework is introduced to improve performance issues, code maintenance (i.e. code duplication), scalability, for improving performance of the network traffic etc. in the dataset. In this work, we examine the Linux Netfilter/iptable, nftable firewall technology. In this paper, a new hybrid approach is proposed where Geometric efficient matching algorithm and stateless firewall optimization algorithm is merged into the code of the Linux iptables and nftables open source firewall for securing Linux web server. "Geometric Efficient Matching algorithm" GEM-iptables & nftables execution manage to filter packets-per-second on a standard system. It is efficient and practical, algorithm for firewall packet matching. While there are a number of paths that can be followed to provide a best malware detection method for firewall security, this work will be beneficial for small enterprises in terms of money and time using Netfilterftables. This makes it easy and simple to configure the strong firewall to solve the security related problems & detect malware using strong firewall rules to achieve optimal level.
机译:随着当今网络技术的稳定发展,网络不仅给我们带来了有益的生产生活,而且随之而来的是一系列网络安全威胁。由于了解威胁,因此对安全性的需求从未如此重要,这就是为什么保护我们的Web服务器和Web资产变得极为重要。防火墙是主要的安全组件,它允许并限制对特定网络和端口的访问。在此研究中,主要重点是设计强大的防火墙过滤规则,以便将恶意代码检测达到最佳水平。引入提出的框架以改善性能问题,代码维护(即代码重复),可扩展性,用于改善数据集中的网络流量的性能等。在这项工作中,我们研究了Linux Netfilter / iptable,可移植的防火墙技术。本文提出了一种新的混合方法,将几何有效匹配算法和无状态防火墙优化算法合并到Linux iptables和nftables开源防火墙的代码中以保护Linux Web服务器。 “几何有效匹配算法” GEM-iptables和nftables的执行设法在标准系统上每秒过滤数据包。它是高效实用的防火墙数据包匹配算法。虽然可以通过多种途径来为防火墙安全性提供最佳的恶意软件检测方法,但这项工作对于使用Netfilter / nftables的金钱和时间而言,对于小型企业将是有益的。这使得配置强大的防火墙以解决安全相关问题和使用强大的防火墙规则检测恶意软件变得容易和简单,以达到最佳级别。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号