期刊文献+

基于IPv4/v6下的IPSec与防火墙协同问题研究 被引量:1

Study on Cooperation of IPv4/v6-Based IPSec and Firewall
原文传递
导出
摘要 针对IPSec与防火墙不能协同工作问题,文中提出了一种解决方案,即将协议头和数据部分分别进行安全处理,并将这种分层思想与密钥协商方法结合,让防火墙介入IPSec的密钥协商阶段,经过协商让加密的数据包通过防火墙,并且通过IDS(入侵检测系统)更进一步的防御非法入侵,从而解决IPSec对防火墙功能的处理问题。实验结果表明,该方法保证了IPSec的安全性,提高了防火墙与IPSec结合时的效率。 For the cooperation question of IPSec and firewall, this paper proposes the solution that handles security problems on protocol head and data in IP datagram separately, combines this layered approach with the key agreement way, and lets the firewall involved in the key agreement phase of IPSec and the encrypted data packets pass, based on consultation, through the firewall, including IDS (Intrusion Detection System) for further defense against intrusion, thus solving the compatibility operation problem. Test results show that this method can ensure the security of IPSec, and raise the efficiency of combination of firewall with IPSec.
出处 《通信技术》 2008年第6期119-121,共3页 Communications Technology
基金 河南省校园示范工程项目504058
关键词 安全关联 密钥协商 入侵检测系统 safe connection (SA) key agreement intrusion detection system
  • 相关文献

参考文献5

二级参考文献17

  • 1唐璐,赵宏.IPsec加密数据流与防火墙过滤模式兼容问题[J].华中科技大学学报(自然科学版),2003,31(S1):141-143. 被引量:2
  • 2何小东,杨路明.防火墙本身的安全问题探析及其对策[J].湖南经济管理干部学院学报,2005,16(1):110-111. 被引量:1
  • 3Kent S, Atk inson R. Security architecture for the internet protocol[EB/OL].http://www.ietf.org/rfc/rfc2401.txt,1998-11-01. 被引量:1
  • 4Harkins D, Carrel D. Internet key exchange[EB/OL]. http://www.ietf.org/rfc/rfc2409.txt, 1998-11-01. 被引量:1
  • 5Kent S,Atkinson R.Security architecture for the internet protocol[S].IETF RFC2401,1998. 被引量:1
  • 6Maughan D,Schertler M,Schneider M,et al.Internet security association and ket management protocol (ISAKMP)[S].RFC 2408,1998. 被引量:1
  • 7Z Yongguang,S Bikramjit.A Multi-Layer IPSec Protocol.The 9th USENIX Security Symposium[EB/OL].http://www.vpnc.org/ietf-ipsec/99.ipsec/msg01831.html,2000. 被引量:1
  • 8S Kent,R Atkinson.IP Authentication Header(AH),RFC 2402[EB/OL].http://www.faqs.org/rfcs/rfc2402.html,1998-11. 被引量:1
  • 9D Harkins,D Carrel.The Internet Key Exchange(IKE),RFC 2409[EB/OL].http://www.faqs.org/rfcs/rfc2409.html,1998-11. 被引量:1
  • 10S Kent,R Atkinson.IP Encapsulating Security Payload(ESP),RFC 2406[EB/OL].http://www.faqs.org/rfcs/rfc2406.html,1998. 被引量:1

共引文献5

同被引文献4

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部