Dissertation > Excellent graduate degree dissertation topics show

The Study of Implementation of the Linux Firewall System

Author: HeMingCong
Tutor: HuJiCheng
School: Wuhan University
Course: Applied Computer Technology
Keywords: Netfilter iptables NAT Packet filtering Linux Firewall
CLC: TP393.08
Type: Master's thesis
Year: 2004
Downloads: 474
Quote: 2
Read: Download Dissertation

Abstract


Because of the huge advantage of open source Linux operating system source code analysis has not only the significance of teaching and research also has significance. However, the current analysis focused memory management, process scheduling, file systems and device drivers for the network, in particular the analysis of the kernel firewall is not enough system. Analyze Linux firewall system is one of the main purpose of this article. Linux firewall implementations to take hierarchical and highly scalable. At the bottom of the foot Netfilter, it provides an abstract, general packet processing framework. Registered by the capture point defined in the Netfilter packet processing functions, packet filtering, network address translation subsystem. Adequate package of the second layer in the Linux kernel firewall subsystem (IP Tables) to the system (Connection Tracking) and trajectory tracking. Package selection subsystem implementations still taking into account scalability, its the organization firewall rules to IP information match (match) target (target), the first by a registered function matching the IP information, if the match is successful, call match (match) processing function to handle the match (match). Such as success, by the goal to decide the fate of the package. The trajectory tracking subsystem is mainly used to implement a firewall with state of its agreement, Assistant expansion. Network Address Translation is in its foundation. The conversion of the implementation of the network address and the packet selection subsystem together, because the rules of its rules and packet selection subsystem is the same concept. So It can be extended target (target) can also be extended on the assistant. Linux firewall technology detail. This paper first introduces the firewall Netfilter framework as well as how to set user space tools iptables Linux firewall, followed by an example of the TCP / IP protocol stack of message processing, then Netfilter achieve the desired data structure followed by a detailed exposition of the realization of the iptables, which described in detail the implementation of packet filtering system finally elaborated connection tracking and NAT implementations. The results of this study have been implemented in the Kingnet SOHO router product stability, performance and efficiency is superior class products give manufacturers a higher rating.

Related Dissertations

  1. Research on Software of TFT-LCD Testing Equipment Based on ARM,TN873.93
  2. Signal Acquisition and Processing Platform Design and Implementation of Trawl Sonar System,S951.2
  3. The Design of Embedded Image Transmission Terminal Based on the TCP/IP Protocol,TP368.1
  4. Study on Dose Verification of IMRT with Film Dosimetry,R815
  5. Borehole imaging device based on embedded systems research,P634.3
  6. IP QoS technology research,TP393.09
  7. Based on the embedded Web technology Research and Implementation of Dynamic Strain Gauge,TP368.1
  8. Ship mountain of e-government network security solutions outside the network design and implementation,TP393.08
  9. The Design and Implementation of a Multi-function Floor Display System in Fire Monitoring Network,TN873
  10. Design and Implementation of Assistant Management System Server Based on Hardware Firewall,TP393.08
  11. The Research and Implementation of Traffic Control System Based on Linux,TP393.06
  12. Design and Implementation of Communication System between Double-chips Based on PCI Bus,TN47
  13. SIP Trunk Gateway NAT traversal solution design and implementation,TN915.05
  14. Security gateway traffic data collection and monitoring agent design and implementation,TN915.08
  15. Based on DM368 HD IP Camera Software System Design and Implementation,TP391.41
  16. Design and Implementation of Port Triggering Function on NAT Gateway,TP393.08
  17. One based on UDP P2P instant communication software design and implementation,TP393.02
  18. Dynamic Traffic Management System Design and Implementation,TP393.06
  19. The Study of Intelligent Intrusion Detection System Based on Neural Network in Linux,TP393.08
  20. The Data Communication Interface Analysis and Study Based on Ethernet/IP Protocol,TP393.04
  21. Design of Temperature and Humidity Intelligent Network Monitoring System Based on ARM9,TP273.5

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile