摘要
介绍了一种实验性的防火墙系统,与传统设计不同之处是其基于PCM模型,可以将每次网络服务请求的IP数据包的路由作为包过滤的根据。这有助于减少防火墙被欺骗的可能性,并在一定程度上避免了外部客户机使用不可信的路由。
This paper discusses an experimental firewall's architecture and implementation. It is based on the PCM security model and filter the packets according to the IP packets'route. Its advantage is to reduce the possibility of spoofing and using of untrusted network routes.
出处
《计算机工程与应用》
CSCD
北大核心
2001年第10期73-75,共3页
Computer Engineering and Applications