论文部分内容阅读
近年来,互联网的规模呈现爆炸性增长,骨干网通信带宽达到了千兆甚至万兆,因此保护互联网的安全变得越来越重要。网络安全领域的各种产品如防火墙、入侵检测系统都是基于对网络数据的分析和预测而开发的,而截获和还原数据的协议还原技术成为设计这些网络安全产品的基石。文章研究并实现了基于Libnids库的Internet网络协议还原系统,该系统利用旁路数据链路帧的方式捕获数据包,借鉴Linux内核的实现方法进行IP分片组装和TCP流重组,有效实现了网络信息内容监控。该系统可以根据需要加入扩展模块,可根据需要还原多种应用层数据。
In recent years, the scale of the Internet has exploded, and backbone network communications have reached a gigahertz or even 10 gigabytes of bandwidth. Therefore, securing the Internet has become more and more important. Various products in the field of network security, such as firewalls and intrusion detection systems, are developed based on the analysis and prediction of network data. Protocol recovery technologies that capture and restore data become the cornerstone of designing these network security products. The article researches and implements the internet protocol restoring system based on Libnids library, which captures data packets by using bypass data link frames and IP fragmentation assembly and TCP flow reorganization by reference to the realization method of Linux kernel, which effectively realizes network Information content monitoring. The system can be added as needed expansion module, according to the need to restore a variety of application layer data.