摘要
介绍了防火墙的发展及各类防火墙的特点,分析了状态检测防火墙的工作原理,建立了状态表和规则表的数据结构,提出了一个基于状态检测的硬件防火墙中协议的整体框架设计。在考虑防火墙安全和速度性能的前提下,给出针对TCP,UDP,ICMP和ARP等TCP/IP协议栈中主要协议的状态检测的结构设计,采用TCP序列号检查、UDP虚连接、ICMP数据包检测引擎等办法保证网络的安全性和高效性。
Introduces the development and characteristic of the firewall, analyses the working principle of the stateful-inspection firewall. The data structure of the state table and rule table is built. Considering the security and performance of the firewall ,presents the structural design for TCP, UDP, ICMP, ARP, which is the main protocol in the TCP/IP stack. Method of TCP sequence number check, UDP virtual conuection,ICMP package inspection easure the security and high performance of the network.
出处
《计算机应用研究》
CSCD
北大核心
2006年第2期101-103,共3页
Application Research of Computers
基金
国防"十五"预研基金资助项目(41316.3.3)
关键词
防火墙
状态检测
协议
Firewall
Stateful-Inspeetion
Protocol