透過您的圖書館登入
IP:18.220.178.207
  • 期刊

校園網路中用戶身分認證過濾系統之實作

Authentication-Based Packet Filter System in Campus Networks

摘要


一般而言,網路管理者根據事先指定好的網路位址,建構出網路位址跟使用者的對應關係。然而,網路位址可以被假造或冒用。因此,對於一位惡意使用網路資源的用戶,可以利用他人的網路位址來避免網路管理員的追查。為了避免固定IP位址與使用者對應關係被誤認,本篇論文提出一個藉由身分認證伺服器跟應用層閘道器(Application Gateway)的結合,精確的辨識出每一條網路連線的使用者。此外,我們的方法亦可以實現在動態取得IP位址的環境,如DHCP。從實驗分析結果,我們的方法跟原本Linux防火牆(iptables)相比並沒有增加太多系統的負擔。

關鍵字

防火牆 身分認證 辨識

並列摘要


In a campus network, a computer is usually setup with one or more fixed IP addresses. If the computer is dedicated to some user, the IP address can then be used to identify the user. However, the IP address can be counterfeited or abused. A user can change the IP address with other's and then can do any wicked network behavior without worrying be caught. The user whose IP address is used by others then becomes a victim. We propose a novel concept of network management by using the combination of a authentication server and a firewall to implement a user-level packet filter system. The system is also well suitable to a network environment which uses dynamic IP address assignment, like DHCP.

並列關鍵字

Firewall authentication iptables DHCP

被引用紀錄


戴興能(2010)。結合身分認證之校園IP管理系統〔碩士論文,國立交通大學〕。華藝線上圖書館。https://doi.org/10.6842/NCTU.2010.00231

延伸閱讀