• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

J4 ›› 2006, Vol. 28 ›› Issue (10): 23-24.

• 论文 • 上一篇    下一篇

基于状态检测的TCP包过滤的设计与硬件实现

迟秀伟 唐朔飞 季振州 李鑫   

  • 出版日期:2006-10-01 发布日期:2010-05-20

  • Online:2006-10-01 Published:2010-05-20

摘要:

状态检测是目前防火墙的主流技术。本文介绍了状态检测防火墙的工作原理,提出了针对TCP数据包状态检测的流程和状态转换的模型,采用了序列号范围检查、动态超时管  理等办法保证系统的安全性,利用哈希算法对状态表进行操作,最终在FPGA上实现。实验结果表明,该设计能很好地适应千兆网络环境。

关键词: 状态检测 防火墙 TCP FPC-A千兆网络

Abstract:

State detection is the main stream of the current firewall technologies. This paper introduces the principle of state detection firewall. The flowchar  t of state detection and the model of state transition for the TCP packets are presented. A method of sequence number scope check and dynamic timeout ma nagement ensures the system security. A hash algorithm is adopted to manage the state table, and the design is implemented on FPC-A. The experiment shows that the design can work well in a Gigabit network environment.

Key words: state detection, firewall, TCP FPGA, Gigabit network