首页> 外文期刊>Network Computing >APPLICATION-LEVEL FIREWALLS: Smaller Net, Tighter Filter
【24h】

APPLICATION-LEVEL FIREWALLS: Smaller Net, Tighter Filter

机译:应用级防火墙:较小的网络,更紧密的过滤器

获取原文
获取原文并翻译 | 示例

摘要

Just when you thought a properly configured firewall would guard your perimeter, along comes the next zero-day vulnerability knocking over your public servers and letting attackers in the front door. Didn't you buy a firewall to stop such attacks? Well, we're going to let you in on a secret: You probably bought a stateful packet-filtering firewall that's effective at blocking network-level attacks but leaves any server available to the world still extremely vulnerable to application-layer attacks. Application-layer firewalls differ from stateful packet-filtering and circuit-level gateways in several ways. First, application-layer firewalls support multiple application proxies on a single firewall. The proxies sit between the client and server passing data between the two endpoints. Suspicious data is dropped and the client and server never communicate directly with each other. Because application-level proxies are application-aware, the proxies can more easily handle complex protocols like H.323, which is used for videoconferencing and VoIP (voice over IP), and Oracle SQL*Net. Application proxies can be transparent to the client and server―no configuration is required on the client or the server―or nontranparent, letting the client and server address the proxy server directly. Transparency versus nontransparency is a matter of implementation and address hiding rather than security.
机译:就在您认为适当配置的防火墙可以保护您的外围设备时,还会出现下一个零日漏洞,该漏洞会破坏您的公共服务器并使攻击者进入前门。您不是购买防火墙来阻止此类攻击吗?好吧,我们要告诉您一个秘密:您可能购买了有状态的数据包筛选防火墙,该防火墙可以有效地阻止网络级攻击,但仍然使世界上任何可用的服务器仍然极易受到应用程序层攻击。应用层防火墙与有状态包过滤和电路级网关在几个方面有所不同。首先,应用程序层防火墙在单个防火墙上支持多个应用程序代理。代理位于客户端和服务器之间,并在两个端点之间传递数据。可疑数据将被丢弃,客户端和服务器之间永远不会直接通信。因为应用程序级代理是应用程序感知的,所以代理可以更轻松地处理诸如视频会议和VoIP(基于IP的语音)的H.323和Oracle SQL * Net之类的复杂协议。应用程序代理对客户端和服务器可以是透明的(不需要在客户端或服务器上进行配置),也可以是非透明的,从而使客户端和服务器直接寻址代理服务器。透明与非透明是实现和地址隐藏而不是安全的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号