• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2006, Vol. 28 ›› Issue (11): 1-3.

• 论文 •    下一篇

基于FreeBSD的包过滤防火墙研究与开发

陈传波 刘清慧 黄刚   

  • 出版日期:2006-11-01 发布日期:2010-05-20

  • Online:2006-11-01 Published:2010-05-20

摘要:

通过对包过滤技术的基本原理进行简要分析,从实现包过滤功能的基本流程出发,本文提出了包过滤型防火墙的形式化模型,结合FreeBSD处理数据包,利用状态监测缓存,使用哈希表提高包过滤规则匹配效率,并根据小型网络系统的安全需求、安全策略介绍了基于FreeBSD操作系统的防火墙设计、系统配置与初步的实现。

关键词: 防火墙 包过滤 状态检测 FreeBSD

Abstract:

The basic principle of packet-filtering is analyzed, and the basic process of implementing packet-filtering functions is also discussed in this paper. A formalized packet-filtering firewall model is presented. By using the Hash table and the stateful-lnspection cache to accelerate matching conditional  rulers, the author implements a packet-filtering firewall based on the FreeBSD operating system, which can serve most small-business systems based on s ecurity needs and strategy.

Key words: firewall, packet-filtering, stateful-inspectlon, freeBSD