软考网络管理员谈防火墙及防火墙的渗透技术(Test the network administrator Technology about firewall and firewall penetration).docVIP
- 1、有哪些信誉好的足球投注网站(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
软考网络管理员谈防火墙及防火墙的渗透技术(Test the network administrator Technology about firewall and firewall penetration) The working principle and advantages and disadvantages of the traditional firewall: 1. (traditional) packet filter firewall works Packet filtering is implemented on the IP layer, so it can be done only with routers. Packet filtering determines whether packets are allowed to pass through header information such as the source IP address, destination IP address, source port, destination port, and packet delivery direction of the packet. Filtering user defined content, such as IP addresses. The principle is that the system checks packets at the network level and is independent of the application layer. Packet filters are widely used because CPU can be used to handle packet filtering with negligible time. Moreover, this protective measure is transparent to users, and when legitimate users are out of the network, they simply can not feel it, and it is very convenient to use. In this way, the system has good transmission performance and easy to expand. But this firewall is not very safe, because the system of application layer information perception -- that is, they do not understand the content of the communication, not filtered at the user level, unable to distinguish different users and prevent IP address embezzlement. If an attacker sets the hosts IP address to a legitimate hosts IP address, it can easily pass through the packet filter, which is more likely to be hacked. Based on this mechanism, the packet filter firewall has the following drawbacks: Communication information: packet filtering firewalls can only access header information of some packets; Communication and application status information: packet filter firewall is stateless, so it is impossible to save state information from communications and applications; Information processing: packet filtering firewalls are limited in their ability to process information. For example, Microsoft IIS vulnerability Un
您可能关注的文档
- 专家给你100条生活秘笈 让你过得更健康快乐(Experts give you 100 Living Tips let you live a happy and healthy).doc
- 专升本英语名词词组和固定搭配(English noun phrases and fixed collocations).doc
- 专外总结(Special summary).doc
- 专业音响 - c-mark 舞台灯光的定义、作用及评论(Professional acoustics - definition, function and commentary of c-mark stage lighting).doc
- 快乐出发(Happy departure).doc
- 快速采聚能量密法(Quick gathering energy density method).doc
- 快速轻松过目不忘背单词(Fast and easy to recite words gifted with an extraordinary retentive memory).doc
- 快速计算某天星期几.(How fast is the day a week).doc
- 快速提高流量 增加成交量(Rapid increase in flow, increase turnover).doc
- 快速有效人气增高操的介绍(Introduction to quick and effective popularity).doc
- 赛车驾驶技术(Racing driving skills).doc
- 赛斯说想像力(Seth says imagination).doc
- 认证培训之一微软.net程序员高级培训教程系列资料(Certification training Microsoft.Net programmers advanced training course series of information).doc
- 陕西黄河集团200mw晶硅太阳能电池生产线建设项目环评公告(Shaanxi the Yellow River group 200MW crystalline silicon solar cell production line construction project EIA announcement).doc
- 邵阳崀山(Shaoyang Lang Mountain).doc
- 设备控制基础习题(Equipment control basic exercises).doc
- 设备搬迁方案(Equipment removal plan).doc
- 设计师常用尺寸(Designer size).doc
- 设计师每日任务(Designer daily tasks).doc
- 设计师资料(Designer information).doc
文档评论(0)