在Windows 7环境中配置Snort作为防火墙

Moath Alsafasfeh, A. Alshbatat
{"title":"在Windows 7环境中配置Snort作为防火墙","authors":"Moath Alsafasfeh, A. Alshbatat","doi":"10.5383/JUSPN.03.02.006","DOIUrl":null,"url":null,"abstract":"Nowadays, computer networks play an important role in our daily live, and the widely use of computer networks are for accessing the internet. The network administrator has a full ability to control all access types to network, and tasked to allow or discard some of the connections. By using Snort Intrusion Detection System (IDS), the network administrator can monitor network access from the sender to the receiver. Snort is one of the IDS, and it is difficult to configure it with closed source operating systems for the purpose of accessing and terminating connections. Moreover, it needs more requirements to work with windows operating system. Snort is compatible with open source operating systems such as Linux but there is a need to configure it with closed source operating systems such as windows operating system. In this paper, Snort is configured with windows 7 operating system so that it will work as a firewall to monitor and terminate connections. This configuration is successfully achieved by identifying new rules in snort package. Using snort IDS, network administrator is able to monitor, allow, and block any accessing to the web with the ability to get alerts containing information related to the connection such as IP address and port numbers. Moreover, a Graphical User Interface (GUI) has been developed to allow end user to configure new snort rules with a user friendly interface depending on snort user requirements. The results indicate that the Snort can be configured with Windows 7 by creating new snort rules to monitor network traffic and terminate connection between two entities. In addition, they show how a GUI allows snort user to create new rules based on him/her requirements.","PeriodicalId":376249,"journal":{"name":"J. Ubiquitous Syst. Pervasive Networks","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-12-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Configuring Snort as a Firewall on Windows 7 Environment\",\"authors\":\"Moath Alsafasfeh, A. Alshbatat\",\"doi\":\"10.5383/JUSPN.03.02.006\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Nowadays, computer networks play an important role in our daily live, and the widely use of computer networks are for accessing the internet. The network administrator has a full ability to control all access types to network, and tasked to allow or discard some of the connections. By using Snort Intrusion Detection System (IDS), the network administrator can monitor network access from the sender to the receiver. Snort is one of the IDS, and it is difficult to configure it with closed source operating systems for the purpose of accessing and terminating connections. Moreover, it needs more requirements to work with windows operating system. Snort is compatible with open source operating systems such as Linux but there is a need to configure it with closed source operating systems such as windows operating system. In this paper, Snort is configured with windows 7 operating system so that it will work as a firewall to monitor and terminate connections. This configuration is successfully achieved by identifying new rules in snort package. Using snort IDS, network administrator is able to monitor, allow, and block any accessing to the web with the ability to get alerts containing information related to the connection such as IP address and port numbers. Moreover, a Graphical User Interface (GUI) has been developed to allow end user to configure new snort rules with a user friendly interface depending on snort user requirements. The results indicate that the Snort can be configured with Windows 7 by creating new snort rules to monitor network traffic and terminate connection between two entities. In addition, they show how a GUI allows snort user to create new rules based on him/her requirements.\",\"PeriodicalId\":376249,\"journal\":{\"name\":\"J. Ubiquitous Syst. Pervasive Networks\",\"volume\":\"8 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2011-12-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"J. Ubiquitous Syst. Pervasive Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.5383/JUSPN.03.02.006\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"J. Ubiquitous Syst. Pervasive Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5383/JUSPN.03.02.006","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

摘要

如今,计算机网络在我们的日常生活中扮演着重要的角色,计算机网络的广泛使用是为了访问互联网。网络管理员完全有能力控制对网络的所有访问类型,并负责允许或丢弃某些连接。通过使用Snort入侵检测系统(IDS),网络管理员可以监视从发送方到接收方的网络访问。Snort是IDS之一,很难用封闭源操作系统配置它来访问和终止连接。此外,它对windows操作系统的要求也更高。Snort与Linux等开放源代码操作系统兼容,但需要将其配置为与windows等封闭源代码操作系统兼容。在本文中,Snort与windows 7操作系统一起配置,这样它就可以作为防火墙来监视和终止连接。通过识别snort包中的新规则,可以成功实现此配置。使用snort IDS,网络管理员能够监视、允许和阻止对web的任何访问,并能够获得包含与连接相关信息(如IP地址和端口号)的警报。此外,还开发了图形用户界面(GUI),允许最终用户根据snort用户需求使用用户友好的界面配置新的snort规则。结果表明,通过创建新的Snort规则来监视网络流量并终止两个实体之间的连接,可以在Windows 7中配置Snort。此外,它们还展示了GUI如何允许snort用户根据自己的需求创建新规则。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Configuring Snort as a Firewall on Windows 7 Environment
Nowadays, computer networks play an important role in our daily live, and the widely use of computer networks are for accessing the internet. The network administrator has a full ability to control all access types to network, and tasked to allow or discard some of the connections. By using Snort Intrusion Detection System (IDS), the network administrator can monitor network access from the sender to the receiver. Snort is one of the IDS, and it is difficult to configure it with closed source operating systems for the purpose of accessing and terminating connections. Moreover, it needs more requirements to work with windows operating system. Snort is compatible with open source operating systems such as Linux but there is a need to configure it with closed source operating systems such as windows operating system. In this paper, Snort is configured with windows 7 operating system so that it will work as a firewall to monitor and terminate connections. This configuration is successfully achieved by identifying new rules in snort package. Using snort IDS, network administrator is able to monitor, allow, and block any accessing to the web with the ability to get alerts containing information related to the connection such as IP address and port numbers. Moreover, a Graphical User Interface (GUI) has been developed to allow end user to configure new snort rules with a user friendly interface depending on snort user requirements. The results indicate that the Snort can be configured with Windows 7 by creating new snort rules to monitor network traffic and terminate connection between two entities. In addition, they show how a GUI allows snort user to create new rules based on him/her requirements.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信