The invention discloses a
network communication security redirection method, comprising the following steps: S1, realizing filtering on process,
IP address, port and protocol target data packets in designated
network communication by virtue of WFP-driven
hierarchical design, and adopting BPF rules for performing pre-
filtration treatment to filter out target
network data packets; S2, setting capture based on a process, an
IP address, a port and a protocol as well as interception, capturing the target
network data packets and performing analysis and restoration according to a TCP / IP
protocol stack, encapsulating the target
network data packets and forwarding; S3, according to a
Socks5 proxy protocol, establishing communication with a
proxy server; and S4, by virtue of the
proxy server and based on the
Socks5 proxy protocol, performing redirection proxy forwarding on the target network data packets, and realizing TCP redirection, UDP redirection and remote DNS redirection. The invention also provides a redirection module, comprising a WFP driving module, a TCP / IP protocol decapsulation module and a redirection
service module and completing TCP redirection, UDP redirection and remote DNS redirection functions.