摘要
文章提出一种提升防火墙数据吞吐量的新方法,引入一台加速引擎的设备,通过实时学习模仿防火墙的安全策略,协同防火墙共同处理网络数据包,降低需要防火墙处理的数据包数量,克服了传统防火墙易于产生性能瓶颈的问题;同时基于Linux/netfilter实现了一个原型系统,并验证了该方案的有效性和可行性。
A new approach of increasing the throughput of the firewall is proposed. An implementor, the so-called firewall accelerator engine is introduced. It can learn the behavior of the firewall and cooperate with it by greatly decreasing the amount of the packets delivered to the firewall. A prototype system based on Linux/netfilter is built to test and verify the scheme. The feasibility of implementing the accelerator engine in real networks is also discussed.
出处
《合肥工业大学学报(自然科学版)》
CAS
CSCD
北大核心
2006年第8期976-979,共4页
Journal of Hefei University of Technology:Natural Science
关键词
防火墙
加速引擎
包过滤
firewall
accelerator engine
packet filtering