基于Windows NDIS过滤驱动的安全软件

Shin-Shung Chen, Tzong-Yih Kuo, Yu-Wen Chen
{"title":"基于Windows NDIS过滤驱动的安全软件","authors":"Shin-Shung Chen, Tzong-Yih Kuo, Yu-Wen Chen","doi":"10.1109/COMPSACW.2013.36","DOIUrl":null,"url":null,"abstract":"We present a new security software based on the NDIS filter drivers at Windows desktop computer, which focuses on filtering and dropping packets according to the snort rules released by security communities (such as Snort or Emerging Threats). TWIDS is an application designed based on the middleware of the Windows® OS, it can identify the application process that transfer packets. TWIDS can process a large number of malicious IP address in the database that it can check and drop packets effectively and improve the network security on Windows® desktop computer by using Snort related protective resources. Thus, it provides a security solution that can help to reduce the investments for network gateway and can be used by common users who used for eliminating the botnet and malware traffic. TWIDS is shared in the downloads section of the Openfoundry.org website, and it will against the spread of botnets and malware.","PeriodicalId":152957,"journal":{"name":"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-07-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Security Software Based on Windows NDIS Filter Drivers\",\"authors\":\"Shin-Shung Chen, Tzong-Yih Kuo, Yu-Wen Chen\",\"doi\":\"10.1109/COMPSACW.2013.36\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"We present a new security software based on the NDIS filter drivers at Windows desktop computer, which focuses on filtering and dropping packets according to the snort rules released by security communities (such as Snort or Emerging Threats). TWIDS is an application designed based on the middleware of the Windows® OS, it can identify the application process that transfer packets. TWIDS can process a large number of malicious IP address in the database that it can check and drop packets effectively and improve the network security on Windows® desktop computer by using Snort related protective resources. Thus, it provides a security solution that can help to reduce the investments for network gateway and can be used by common users who used for eliminating the botnet and malware traffic. TWIDS is shared in the downloads section of the Openfoundry.org website, and it will against the spread of botnets and malware.\",\"PeriodicalId\":152957,\"journal\":{\"name\":\"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-07-22\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/COMPSACW.2013.36\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE 37th Annual Computer Software and Applications Conference Workshops","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMPSACW.2013.36","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

我们提出了一种基于Windows桌面计算机上的NDIS过滤器驱动程序的新安全软件,它的重点是根据安全社区发布的snort规则(如snort或新兴威胁)过滤和丢弃数据包。TWIDS是基于Windows®操作系统中间件设计的应用程序,它可以识别传输数据包的应用程序进程。TWIDS可以对数据库中大量的恶意IP地址进行处理,有效地检查和丢弃报文,利用Snort相关的防护资源,提高Windows®桌面计算机的网络安全性。因此,它提供了一种安全解决方案,可以帮助减少网络网关的投资,并可用于消除僵尸网络和恶意软件流量的普通用户。TWIDS在openfoundy.org网站的下载部分共享,它将防止僵尸网络和恶意软件的传播。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Security Software Based on Windows NDIS Filter Drivers
We present a new security software based on the NDIS filter drivers at Windows desktop computer, which focuses on filtering and dropping packets according to the snort rules released by security communities (such as Snort or Emerging Threats). TWIDS is an application designed based on the middleware of the Windows® OS, it can identify the application process that transfer packets. TWIDS can process a large number of malicious IP address in the database that it can check and drop packets effectively and improve the network security on Windows® desktop computer by using Snort related protective resources. Thus, it provides a security solution that can help to reduce the investments for network gateway and can be used by common users who used for eliminating the botnet and malware traffic. TWIDS is shared in the downloads section of the Openfoundry.org website, and it will against the spread of botnets and malware.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信