欢迎来到天天文库
浏览记录
ID:19791202
大小:1.06 MB
页数:31页
时间:2018-10-06
《firewall categorization methods》由会员上传分享,免费在线阅读,更多相关内容在教育资源-天天文库。
1、FirewallCategorizationMethodsFirewallscanbecategorizedbyprocessingmode,developmentera,orintendedstructureFiveprocessingmodesthatfirewallscanbecategorizedbyare:PacketfilteringApplicationgatewaysCircuitgatewaysMAClayerfirewallsHybridsFirewallsCategorizedbyDevelopmentGener
2、ationFirstgeneration:staticpacketfilteringfirewallsSecondgeneration:application-levelfirewallsorproxyserversThirdgeneration:statefulinspectionfirewallsFourthgeneration:dynamicpacketfilteringfirewalls;allowonlypacketswithparticularsource,destinationandportaddressestoente
3、rFifthgeneration:kernelproxies;specializedformworkingunderkernelofWindowsNTPacketFiltersEitherblockorallowtransmissionofpacketsofinformationbasedoncriteriasuchasport,IPaddress,andprotocolReviewtheheader,stripitoff,andreplaceitwithanewheaderbeforesendingittoaspecificloca
4、tionwithinthenetworkFundamentalcomponentsoffirewallsViewingHeaderContentsTheUseofRulesTheUseofRulesStatefulPacketFilteringDual-HomedHostProxyServerConfigurationFigure8-3SymmetricEncryptionExampleCryptographicAlgorithmsDataEncryptionStandard(DES):oneofmostpopularsymmetri
5、cencryptioncryptosystems64-bitblocksize;56-bitkeyAdoptedbyNISTin1976asfederalstandardforencryptingnon-classifiedinformationTripleDES(3DES):createdtoprovidesecurityfarbeyondDESAdvancedEncryptionStandard(AES):developedtoreplacebothDESand3DESCryptographicAlgorithmsAsymmetr
6、icEncryption(publickeyencryption)Usestwodifferentbutrelatedkeys;eitherkeycanencryptordecryptmessageIfKeyAencryptsmessage,onlyKeyBcandecryptHighestvaluewhenonekeyservesasprivatekeyandtheotherservesaspublickeyFigure8-4UsingPublicKeysAPublicKeyGeneratedbyPGPNetworkAddressT
7、ranslation(NAT)Used,bymostfirewalls,toshieldaprivatenetworkfromoutsideinterferenceTranslatesbetweenprivateaddressesinsideanetworkandpublicaddressesoutsidethenetworkDonetransparently(unnoticedbyexternalcomputers)InternalIPaddressesremainhiddenPerformedbyNATproxyserversUs
8、esanaddresstabletodotranslationsEx:acomputerinsideaccessesacomputeroutsideChangesourceIPaddresstoitsownaddress
此文档下载收益归作者所有