The Design of a Secure Internet Gateway
暂无分享,去创建一个
The Internet supports a vast and growing community of computers users around the world. Unfortunately, this network can provide anonymous access to this community by the unscrupulous, careless, or dangerous. On any given Internet there is a certain percentage of poorly-maintained systems. AT&T has a large internal Internet that we wish to protect from outside attacks, while providing useful services between the two. This paper describes our Internet gateway. It is an application-level gateway that passes mail and many of the common Internet services between our internal machines and the Internet. This is accomplished without IP connectivity using a pair of machines: a trusted internal machine and an untrusted external gateway. These are connected by a private link. The internal machine provides a few carefully-guarded services to the external gateway. This configuration helps protect the internal internet even if the external machine is fully compromised.
[1] David L. Presotto,et al. Interprocess communication in the ninth edition unix system , 1990, Softw. Pract. Exp..
[2] David L. Presotto,et al. Upas—a simpler approach to network mail , 1990 .
[3] S. M. Bellovin,et al. Security problems in the TCP/IP protocol suite , 1989, CCRV.
[4] Donn Seeley,et al. A Tour of the Worm , 1988 .