• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2014, Vol. 36 ›› Issue (08): 1486-1492.

• 论文 • Previous Articles     Next Articles

Research of the linkage system of firewall
and intrusion detection system based on ACE and SSL                   

MA Zhanfei1,YIN Chuanzhuo2   

  1. (1.Baotou Teachers College,Inner Mongolia University of Science and Technology,Baotou 014030;2.School of Information Engineering,Inner Mongolia University of Science and Technology,Baotou 014010,China)
  • Received:2013-01-17 Revised:2013-04-16 Online:2014-08-25 Published:2014-08-25

Abstract:

With the rapid development of Internet, some intelligent attack methods and techniques are increasing. The network is easily attacked by hackers or malicious software. The safty problem is increasingly outstanding in computer network. The traditional technologies of firewalls and Intrusion Detection Systems (IDSs) own poor security, high false alarm rate, and low level of intelligence. Considering the demands of obtaining integrity and dynamics in network security, a novel linkage system model of firewall and IDS based on open communication platform of ACE (Adaptive Communication Environment) and SSL (Secure Socket Layer) is proposed. This system model combines the advantages of firewall and IDS, and uses the encrypted information transmission mechanism, and the policy management mechanism, and the associated linkage analysis algorithms to ensure the reliability, integrity and confidentiality of the transmitted information. Experimental results show that the linkage system can effectively prevent network from attacks, and possesses better cooperativeness, universalness and expansibility.:

Key words: network security;intrusion detection system;firewall; linkage;middleware