{"title":"基于Windows NDIS过滤驱动的安全软件","authors":"Shin-Shung Chen, Tzong-Yih Kuo, Yu-Wen Chen","doi":"10.1109/COMPSACW.2013.36","DOIUrl":null,"url":null,"abstract":"We present a new security software based on the NDIS filter drivers at Windows desktop computer, which focuses on filtering and dropping packets according to the snort rules released by security communities (such as Snort or Emerging Threats). TWIDS is an application designed based on the middleware of the Windows® OS, it can identify the application process that transfer packets. TWIDS can process a large number of malicious IP address in the database that it can check and drop packets effectively and improve the network security on Windows® desktop computer by using Snort related protective resources. Thus, it provides a security solution that can help to reduce the investments for network gateway and can be used by common users who used for eliminating the botnet and malware traffic. TWIDS is shared in the downloads section of the Openfoundry.org website, and it will against the spread of botnets and malware.","PeriodicalId":152957,"journal":{"name":"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Security Software Based on Windows NDIS Filter Drivers\",\"authors\":\"Shin-Shung Chen, Tzong-Yih Kuo, Yu-Wen Chen\",\"doi\":\"10.1109/COMPSACW.2013.36\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We present a new security software based on the NDIS filter drivers at Windows desktop computer, which focuses on filtering and dropping packets according to the snort rules released by security communities (such as Snort or Emerging Threats). TWIDS is an application designed based on the middleware of the Windows® OS, it can identify the application process that transfer packets. TWIDS can process a large number of malicious IP address in the database that it can check and drop packets effectively and improve the network security on Windows® desktop computer by using Snort related protective resources. Thus, it provides a security solution that can help to reduce the investments for network gateway and can be used by common users who used for eliminating the botnet and malware traffic. TWIDS is shared in the downloads section of the Openfoundry.org website, and it will against the spread of botnets and malware.\",\"PeriodicalId\":152957,\"journal\":{\"name\":\"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-07-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/COMPSACW.2013.36\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMPSACW.2013.36","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Security Software Based on Windows NDIS Filter Drivers
We present a new security software based on the NDIS filter drivers at Windows desktop computer, which focuses on filtering and dropping packets according to the snort rules released by security communities (such as Snort or Emerging Threats). TWIDS is an application designed based on the middleware of the Windows® OS, it can identify the application process that transfer packets. TWIDS can process a large number of malicious IP address in the database that it can check and drop packets effectively and improve the network security on Windows® desktop computer by using Snort related protective resources. Thus, it provides a security solution that can help to reduce the investments for network gateway and can be used by common users who used for eliminating the botnet and malware traffic. TWIDS is shared in the downloads section of the Openfoundry.org website, and it will against the spread of botnets and malware.