摘要
提出一种在虚拟磁盘中对文件映像前后的访问进程进行监控并对非法信息流进行过滤的方法。该方法在关键字或特征信息提取过程中安装各种钩子并对接入主机进行审计,用来提高系统服务器的包转发速率与非法信息的捕捉能力。其目的是阻止病毒或木马程序对文件破坏或数据包劫持,保证信息接入的可控性和安全性。实验测试表明,系统降低了包转发时延,提高了包转发速率和非法信息的识别能力。
The paper presents a method that monitors the access process of the virtual disk file image before and after and using illegal information flow filter drivers. There install a lot of host audit hooks on host audit system during the extraction of the keywords or characteristic information, in order to improve the packet forwarding rate of the server and the capturing ability of ille- gal information. Its purpose is to prevent document from destruction by virus or Trojan program, and achieve controllability and safe- ty in information access. Finally, we perform an experiment through IxLoad. The results of the experiment show that the system can reduce the packet forward delay, improve the packet forwarding rate and better the recognizing ability of illegal information.
出处
《微型机与应用》
2013年第20期51-53,56,共4页
Microcomputer & Its Applications
基金
国家自然科学基金资助项目(51074097)
关键词
网络信息安全
进程防火墙
虚拟磁盘技术
非法信息流
内核钩子
过滤代价
network information security
process firewa11
virtual disk technology
illegal information flow
kernel hooks
filtering cost