摘要
通过对包过滤技术的基本原理进行简要分析,从实现包过滤功能的基本流程出发,本文提出了包过滤型防火墙的形式化模型,结合FreeBSD处理数据包,利用状态监测缓存,使用哈希表提高包过滤规则匹配效率,并根据小型网络系统的安全需求、安全策略介绍了基于FreeBSD操作系统的防火墙设计、系统配置与初步的实现。
The basic principle of packet-filtering is analyzed, and the basic process of implementing packet-filtering functions is also discussed in this paper. A formalized packet-filtering firewall model is presented. By using the Hash table and the stateful-lnspection cache to accelerate matching conditional rulers, the author implements a packet-filtering firewall based on the FreeBSD operating system, which can serve most small-business systems based on security needs and strategy.
出处
《计算机工程与科学》
CSCD
2006年第11期1-3,共3页
Computer Engineering & Science