期刊文献+

一种真实场景下的防火墙TCP参数调优方法

原文传递
导出
摘要 防火墙是一种广泛使用的安全防护设备,国家电网公司在邮件系统一级部署的工作过程中,出现防火墙中TCP连接数过多的问题。本文通过详细分析TCP连接建立、保持、关闭过程中存在的每一个状态,总结出TCP连接数过多的原因,并具体说明了迪普和天融信两种防火墙的会话参数调优方法。
作者 夏飞
出处 《网络安全技术与应用》 2015年第5期188-189,共2页 Network Security Technology & Application
  • 相关文献

参考文献3

二级参考文献11

  • 13.Stevens95Wright G R,Stevens W R.TCP/IP Illustrated Volume2: The Implementation.Addison-Wesley,Reading,Mass,1995
  • 2Dharmapurikar S, Paxson V. Robust TCP Stream Reassembly in the Presence of Adversaries[C]//Proc. of the 14th Conference on USENIX Security Symposium. Baltimore, USA: ACM Press, 2005.
  • 3Thompson K, Miller G, Wilder R. Wide-area Internet Traffic Patterns and Characteristics[J]. IEEE Communications Society, 1997, 11(6): 10-23.
  • 4Song Haoyu, Dharmapurikar S, Turner J, et al. Fast Hash Table Lookup Using Extended Bloom Filter: An Aid to Network Processing[J]. ACM SIGCOMM Computer Com- munication Review, 2005, 35(4): 181-192.
  • 5Li Xin, Ji Zhengzhou, Hu Mingzeng. Stateful Inspection Firewall Session Table Processing[J]. International Journal of Information Technology, 2005, 11(2): 21-30.
  • 6Roesch M. Snort-lightweight Intrusion Detection for Net- works[C]//Proc. of the 13th USENIX Conference on System Administration. Seattle, USA: ACM Press, 1999.
  • 7Paxson V. Bro: A System for Detecting Network Intruders in Real Time[J]. Computer Networks, 1999, 31(23): 2435-2463.
  • 8Oh J, Kim B, Yoon S, et al. Architecture and Mechanisms for Implementing an FPGA-based Stateful Intrusion Detection System[J]. International Journal of Computer Science and Network Security, 2007, 7(5): 110-117.
  • 9Yoon S, Kim B, Oh J, et al. High Performance Session State Management Scheme for Stateful Packet Inspection[C]//Proc. of the 10th Asia-Pacific Conference on Network Operations and Management Symposium: Managing Next Generation Networks and Services. Berlin, Germany: Springer-Verlag, 2007.
  • 10Kim H, Kim J H, Kang I, et al. Preventing Session Table Explosion in Packet Inspection Computers[J]. IEEE Transactions on Computers, 2005, 54(2): 238-240.

共引文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部