首页> 外文期刊>International journal of critical infrastructure >Network security mechanisms utilising network address translation
【24h】

Network security mechanisms utilising network address translation

机译:利用网络地址转换的网络安全机制

获取原文
获取原文并翻译 | 示例
           

摘要

A new protocol technology is just starting to emerge from the laboratory environment. Its stated purpose is to provide a means whereby networks, and the services that reside on them, can be protected from adversarial compromise. This protocol called Dynamic Network Address Translation (Dynat) is designed to protect computer networks against cyber attacks. Briefly, Dynat changes network parameters, such as the IP address and port numbers, between communication sessions and even during sessions. As a result, an adversary cannot associate activity on a given port of a given IP address with an application on a particular computer, thereby presenting a significant barrier to network attacks. This paper identifies the major components or attributes that are associated with the Dynat protocol and describes some of the potential implementations and associated network architectures that can deploy Dynat. It examines inter-operability issues associated with Dynat's interaction with other network protocols along with its impact on standard security implementations, such as IPSec and Intrusion Detection Systems.
机译:一种新的协议技术刚刚从实验室环境中出现。其既定目的是提供一种手段,使网络及其上的服务可以免受对抗性攻击。此协议称为动态网络地址转换(Dynat),旨在保护计算机网络免受网络攻击。简而言之,Dynat会在通信会话之间甚至在会话期间更改网络参数,例如IP地址和端口号。结果,攻击者无法将给定IP地址的给定端口上的活动与特定计算机上的应用程序相关联,从而给网络攻击带来了重大障碍。本文确定了与Dynat协议关联的主要组件或属性,并描述了一些可以部署Dynat的潜在实现方式和相关的网络体系结构。它检查与Dynat与其他网络协议的交互相关的互操作性问题,以及它对IPSec和入侵检测系统等标准安全性实现的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号