期刊文献+

基于加速引擎的防火墙部署方案

Improving the firewall through the accelerator engine
下载PDF
导出
摘要 文章提出一种提升防火墙数据吞吐量的新方法,引入一台加速引擎的设备,通过实时学习模仿防火墙的安全策略,协同防火墙共同处理网络数据包,降低需要防火墙处理的数据包数量,克服了传统防火墙易于产生性能瓶颈的问题;同时基于Linux/netfilter实现了一个原型系统,并验证了该方案的有效性和可行性。 A new approach of increasing the throughput of the firewall is proposed. An implementor, the so-called firewall accelerator engine is introduced. It can learn the behavior of the firewall and cooperate with it by greatly decreasing the amount of the packets delivered to the firewall. A prototype system based on Linux/netfilter is built to test and verify the scheme. The feasibility of implementing the accelerator engine in real networks is also discussed.
出处 《合肥工业大学学报(自然科学版)》 CAS CSCD 北大核心 2006年第8期976-979,共4页 Journal of Hefei University of Technology:Natural Science
关键词 防火墙 加速引擎 包过滤 firewall accelerator engine packet filtering
  • 相关文献

参考文献9

  • 1Gupta P, McKeown N. Packet classification on multiple fields[A]. Proceedings of the SIGCOMM[C]. New York:ACM , 1999. 147-160.
  • 2NetScreen Technologies Inc. Stateful inspection firewall:the NetScreen way [EB/OL]. http://www.netscreen.com, 2003-06-12.
  • 3Benecke C.A parallel packet screen for high speed networks [A].Proceedings of 15th Annual Computer Security Applications Conference[C].Los Alamitos, Calif, 1999, 115 - 128.
  • 4Bellovin S M. Distributed firewalls[J]. Login Magazine:Special Issue on Security, 1999, (11) :37-39.
  • 5刘晖,李之棠.提高防火墙性能的技术手段[J].信息安全与通信保密,2004(1):43-44. 被引量:3
  • 6Netfilter Coreteam. The netfilter/iptables howtos [EB/OL]. http://www. netfilter.org, 2004-08-15.
  • 7张佳,赵静凯,崔伟,黄皓.基于状态检测的TCP包过滤在Linux下的实现方法[J].计算机工程与应用,2004,40(11):152-155. 被引量:3
  • 8ZTI. LanTraffic user's guides[EB/OL].http://www.ztitelecom.com/pages/main-lantrafficv2.htm, 2003-07-05.
  • 9Jemec M. Ethernet packet generator [EB/OL]. http://packeth.sourceforge.net, 2003-04-08.

共引文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部