J4 ›› 2006, Vol. 28 ›› Issue (10): 23-24.
• 论文 • 上一篇 下一篇
迟秀伟 唐朔飞 季振州 李鑫
出版日期:
发布日期:
Online:
Published:
摘要:
状态检测是目前防火墙的主流技术。本文介绍了状态检测防火墙的工作原理,提出了针对TCP数据包状态检测的流程和状态转换的模型,采用了序列号范围检查、动态超时管 理等办法保证系统的安全性,利用哈希算法对状态表进行操作,最终在FPGA上实现。实验结果表明,该设计能很好地适应千兆网络环境。
关键词: 状态检测 防火墙 TCP FPC-A千兆网络
Abstract:
State detection is the main stream of the current firewall technologies. This paper introduces the principle of state detection firewall. The flowchar t of state detection and the model of state transition for the TCP packets are presented. A method of sequence number scope check and dynamic timeout ma nagement ensures the system security. A hash algorithm is adopted to manage the state table, and the design is implemented on FPC-A. The experiment shows that the design can work well in a Gigabit network environment.
Key words: state detection, firewall, TCP FPGA, Gigabit network
迟秀伟 唐朔飞 季振州 李鑫. 基于状态检测的TCP包过滤的设计与硬件实现[J]. J4, 2006, 28(10): 23-24.
0 / / 推荐
导出引用管理器 EndNote|Ris|BibTeX
链接本文: http://joces.nudt.edu.cn/CN/
http://joces.nudt.edu.cn/CN/Y2006/V28/I10/23