服务语义事件的监测、分析以及控制
Monitor, analysis and control of service semantic events
Linux防火墙允许用户定义一系列规则,借此来控制数据包出入系统,尤其是防火墙的内核模块netfilter更是提供了数据包捕获的功能,能够允许用户自定义对数据包的分析操作。本文则提供了一种对物联网服务通信过程中的监控以及分析的功能,通过在物理网卡上捕获数据包并分析来得到数据包所代表的抽象事件,与已知事件对比来判断其合法性;同时,判断其在整个流程走向中的合法性;如果两层合法性都满足,则放其通过;否则,调用防火墙处理并丢包。
Linux firewall permits users to define a set of rules to control legitimate packets access system, especially the netfilter kernel module of the firewall is to provide a packet capture feature that allows users to customize the data packet analysis operation. This article provides monitoring and analysis capabilities in the process of networking services, through the physical network card packet capture and analysis, to get the abstract event represented by data packet and compare with the given events to judge legality, and at the same time, to determine its legitimacy in the whole process. If two kinds of legality are met, then put the data packet through; otherwise, firewall processing will be called and packet discarded.
章洋、王兴
通信
计算机应用技术linux防火墙物联网服务抽象事件
computer application technologylinux firewallIOT serviceabstract events
章洋,王兴.服务语义事件的监测、分析以及控制[EB/OL].(2015-12-04)[2025-08-02].http://www.paper.edu.cn/releasepaper/content/201512-249.点此复制
评论