You are here: hacking technology > firewall > Content
Hot Articles
Recommend Articles
New Articles
Outside the distributional firewall's application deployment robs the thief within family together a
  Add date: 10/09/2008   Publishing date: 10/09/2008   Hits: 1
Total 3 pages, Current page:1, Jump to page:
 
Along with the broad electric network's unceasing development, we organized richly colorful had the broad electricity characteristic open-door policy, but the following network security problem day by day has also received our attention, to guarantee that the website the security normal operation, the network administrator using network products and so on firewall, router carried on the safety protection, these played prevented “the outside” the attack and the invasion role objectively, but this tradition's firewall technology (was named boundary firewall) to be able to prevent from the exterior majority of attacks, existed in name only regarding the confined internal invasion. Therefore, was born one kind to use in isolating, stopping up the emerging firewall technology - - distributional firewall which specially the intranet leaked.

   First, distributional firewall's technical characteristic

   1.1 main engine presences

   The distributional firewall's most main feature selects the main engine presence method, therefore called that it “the main engine firewall”, its key character is the presence, in is protected on main engine, outside this main engine's network, no matter is occupies outside the network interior or the network thought that may not trust, the service which therefore may aim at on this main engine to move the concrete application which and provides outward to establish the pointed very strong security policy. The main engine firewall to the distributional firewall architecture's outstanding contributions is, causes the security policy not only to pause between the network and the network, but extends the security policy promotion to each network end-point.

   1.2 inserting operating system essence

   This was mainly aims at the present pure software type distributional firewall, for own security and stopped up operating system's crack thoroughly, the main engine firewall's safe monitor core engine must inlay the person operating system essence the shape movement, took over control the network card directly, after carried on all data packet the inspection submitted the operating system again. Cannot realize this kind of distributional movement pattern main engine firewall, because receives the operating system secure restriction, has the obvious safe hidden danger.

   1.3 are similar to individual firewall

   Individual firewall is one kind of software firewall product, it is before the distributional firewall already appears a kind of firewall product, it uses for to protect the sole main engine system. Distributional has the similarity in view of the tabletop application's main engine firewall with individual firewall, if they correspond individual system, but its difference is also essential. First their mode of administration is totally different, the individual firewall's security policy establishes by system user, the goal is against exterior attack, but in view of the tabletop application's main engine firewall's security policy from overall system's manager unified agreement and the establishment, besides plays the protective function to this tabletop machine, may also control visit to this tabletop machine foreign, and this kind of safety mechanism is the tabletop machine user not obviously and cannot modify.

 
Other pages: : 1 * 2 * 3 * Next>>
Prev:How refuses to threaten teaches you reasonably to dispose the firewall highly effective

Comment:

Category: Home > firewall