摘要:
Defense against distributed denial of service(DDoS) is one of the hardest security problems on the Internet.Netfilter is an excellent firewall framework that has plain structure to extend conveniently,and is adopted during the Linux kernel 2.4 and the subsequent versions.This paper introduces the design of a hardware firewall that is realized by netfilter hook functions,and it defends the DDoS attack.As it shown by research result,the kernel level firewall has an efficient performance,and can works actively when defending DDoS attack.
展开