DocumentCode :
3355549
Title :
Research and Design of NIDS Based on Linux Firewall
Author :
Jia, Zongpu ; Liu, Shufen ; Wang, Guowei
Author_Institution :
Sch. of Comput. Sci. & Technol., Jilin Univ., Changchun
fYear :
2006
fDate :
3-5 Aug. 2006
Firstpage :
556
Lastpage :
560
Abstract :
Firewall has many shortages, such as it cannot keep away interior attacks, it cannot provide a consistent security strategy, and it has a single bottleneck spot and invalid spot, etc. Intrusion detection system (IDS) also has many defects, such as low detection ability, lack of effective response mechanism, poor manageability, etc. If firewall and IDS are integrated, the cooperation of them can implement the network security to a great extent: on the one hand, IDS monitors the network, provides a real- time detection of attacks from the interior and exterior, and automatically informs firewall and dynamically alters the rules of firewall once an attack is found; on the other hand, firewall loads dynamic rules to hold up the intrusion, controls the data traffic of IDS and provides the security protection of IDS. Based on constructing firewall with Iptables in the environment of Linux OS, the respective characters of firewall and IDS are analyzed. Then, the viewpoint of integrating firewall and IDS to realize the network security is proposed, and the application and algorithm of intrusion detection are systemically analyzed and designed
Keywords :
Linux; authorisation; computer networks; telecommunication security; Iptables; Linux OS; Linux firewall; network security; network-based intrusion detection system; security protection; Access control; Algorithm design and analysis; Communication system security; Computer science; Data security; Information filtering; Information filters; Intrusion detection; Linux; Protection; Iptables; Linux; firewall; network intrusion detection; network security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Pervasive Computing and Applications, 2006 1st International Symposium on
Conference_Location :
Urumqi
Print_ISBN :
1-4244-0326-x
Electronic_ISBN :
1-4244-0326-x
Type :
conf
DOI :
10.1109/SPCA.2006.297482
Filename :
4079053
Link To Document :
بازگشت