Design and Implementation of Client IP Notification Feature on DNS for Proactive Firewall System

Design and Implementation of Client IP Notification Feature on DNS for Proactive Firewall System
复制标题

主动防火墙系统DNS客户端IP通知功能的设计与实现

DOI:
10.1109/compsac.2015.220
复制
发表时间:
2015
期刊:
Proc. of The 39th Annual International Computer Software & Applications Conference (COMPSAC2015/ADMNET WS)
影响因子:
--
通讯作者:
Yong Jin
Yong Jin
中科院分区:
--
文献类型:
--
作者:
Tomokazu Otsuka;Gada;Nariyoshi Yamai;Kiyhiko Okayama;Yong Jin

文献摘要

相似文献

从互联网对组织内部计算机的恶意访问和攻击从未停止,每种技术都需要相应的对策。大多数组织引入一些防火墙设施,作为保护其内部计算机和网络免受这些攻击的解决方案之一。但是,在大多数组织中,网络管理员必须根据三层和四层信息在防火墙系统上手动部署策略,并且只有识别出的通信对等体才能被基于策略的防火墙系统控制。为了解决这些问题,我们重点研究了发生在大多数TCP/IP通信之前的域名解析,并提出了一种新的机制:基于DNS查询发起者的自适应可调查防火墙系统,通过将DNS查询端客户端IP地址通知到目标DNS服务器。本文主要介绍了在实际应用DNS扩展标准(EDNS0)的情况下,通过嵌入查询源客户端的子网地址和子网掩码,在缓存DNS服务器中实现客户端IP地址通知功能的详细设计和实现。
The attempts of malicious access and attacks from the Internet to the internal computers of organizations never stop today and corresponding countermeasure for each technique is required. Most organizations introduce some firewall facilities as one of the solutions to protect their internal computers as well networks from those attacks. However, in most organizations, the network administrator has to deploy the policies on the firewall system manually based on the layer 3 and 4 information and only identified communication peers can be controlled by the policy-base firewall system. To solve these problems, we focused on the domain name resolution which happens prior to most TCP/IP communications and approach a new mechanism: adaptively investigable firewall system based on DNS query initiator by notifying the DNS query side client IP address to the target DNS server. In this paper, we mainly present the detail of design and implementation of the client IP address notification feature in the caching DNS server by embedding the subnet address as well as subnet mask of the query source client by practically using the DNS expanded standard (EDNS0).