Application of Switch ACL in WWW Server Security Protection
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    This study is designated to solve the problem of that server system and software’s security configurations can be reset after the server is invaded, and the network security equipment (hardware firewall, etc.) has large granularity. We analyze common network applications of WWW server, such as WWW, DNS, and FTP, summarize of the characteristics of each network application protocol, and according to the principle of dynamic port fixation and dynamic managerment IP fixation, configure the server access switch ACL, then apply each server’s ACL to the server-connected switch port, protect the server specially. When the server firewall rules are disabled, the server access switch ACL can limit the behavior of the server, thus protecting the servers and the intranet network devices. Using the Pktgen tool based on INTEL DPDK (Data Plane Development Tool) to test, ACL in the server access switch can filter the high abnormal traffic from the server and protect the network and equipment.

    Reference
    Related
    Cited by
Get Citation

单庆元,阎丕涛,南峰.交换机ACL在WWW服务器安全防护中的应用.计算机系统应用,2019,28(12):212-218

Copy
Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:May 17,2019
  • Revised:June 21,2019
  • Adopted:
  • Online: December 13,2019
  • Published: December 15,2019
Article QR Code
You are the firstVisitors
Copyright: Institute of Software, Chinese Academy of Sciences Beijing ICP No. 05046678-3
Address:4# South Fourth Street, Zhongguancun,Haidian, Beijing,Postal Code:100190
Phone:010-62661041 Fax: Email:csa (a) iscas.ac.cn
Technical Support:Beijing Qinyun Technology Development Co., Ltd.

Beijing Public Network Security No. 11040202500063