標題: 具有網路安全防衛系統的閘道器
A Gateway Incorporated with a Defense System for Network Security
作者: 馮忠信
Feng, Chung-Hsin
關鍵字: Gateway;網路閘道器;Network Security;Linux Security Module(LSM);網路安全;LSM
出版社: 電機工程學系所
在網路的蓬勃發展之下,有越來越多的應用都架構於網路上。但是隨著網路使用的範圍越來越廣泛,網路攻擊的問題也層出不窮。於是,系統的安全性便需要加以提升來避免被入侵或是攻擊。尤其,當有更多的裝置皆具有連接網際網路的功能時,勢必會使用閘道器來互相連接,分享網際網路的資源,因此,閘道器的安全性也必須更注意。Linux Security Module(LSM)是一個介於Kernel API和User Application之間的介面,它利用掛載模組的方式,讓我們可以將自己所設計的安全機制整合於Kernel中。本系統利用LSM提供多個稱作Security Hook的函數指標,發展防禦機制來防止後門程式、蠕蟲攻擊、PortScan與SYN Flooding攻擊等,並且實現於IXDPG425的平台上,也具有NAT和DHCP的功能。另外也將運行中的資訊與防禦的結果作記錄,提供給管理者參考與查詢。

Since the growing development of Internet technology, there is more and more application on Internet. But when network used more and more extensive, the network attack occurs more often. Consequently the system needs to improve security, and to avoid being attacked or invaded. In addition when more devices have capability to connect Internet, must use Gateway to connect each other and share Internet. So the Gateway must to improve security too. The Linux Security Module (LSM) is interface with Kernel API and User Application. It use the way of “Load Module”, enable our security rules combine in Kernel. This paper implement Gateway includes both NAT and DHCP on platform of IXDPG425. Besides we implement security rules with LSM to against backdoor, worms, port scans, SYN flooding attack. We also offer system's logs and protection of results for administers to look up and research.
