CN1574792B

Multi-layer based method for implementing network firewalls

Abstract

Provides a method, a method for a firewall of the fire wall structure. The fire structure comprises multiple network layer and a first machine. The two-stage transmitting the data packet and information packet information to the first a host, and data packet context and transmitting and then each, and processing data packets. The first a single time with one or more filtering and information packet information the images, and is connected to the operation to these layer, wherein pointed of how handle to the information packet.

Term

Term ended

Expired 3 June 2024, 2.3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

15 claims: 6 independent, 9 dependent

  1. 1
    The is a request stage operating a strategy's method, wherein the support stage is a framework one of multiple stages; the framework fire - comprising with multiple mounting filters' a engine, the is composed characterised, comprising:Connected with the support table, which are multiple stages the preceding stage receiving information, packets Connected with the support table, wherein the preceding stage receiving information packet context data structure, wherein the data packet high and low invention comprises with the data packet with the preceding table;data Connected with the support table, externally connected with the data packet the related parameter acquisition;Output end of the classifying to transfer, and classifying to transfer comprising a packet information associated wherein the parameter acquisition;Wherein the information packet parameter acquisition to compare with multiple filter of filtering and comprises a matching to the information packet parameter acquisition at least filter and is connected with a policy at least filter;assigns The response a classifying to exchange according, with a a policy arranged on the operation. 一种用于在请求阶段执行防火墙策略的方法,所述请求阶段是防火墙构架中的多个阶段之一,所述防火墙构架进一步包括具有多个被安装的滤波器的防火墙引擎,其特征在于,包括:通过所述请求阶段,从所述多个阶段中的前一个阶段接收信息包;通过所述请求阶段,从所述前一个阶段接收信息包上下文数据结构,所述信息包上下文包括与所述信息包关联的前一个阶段的数据;通过所述请求阶段,识别与所述信息包关联的参数集;发出分类调用,所述分类调用包括与所述信息包关联的所述参数集;将所述信息包参数集与多个滤波器的滤波条件进行比较并识别匹配所述信息包参数集的至少一个滤波器和由所述至少一个滤波器指定的关联的防火墙策略;响应于所述分类调用,根据所述关联的防火墙策略来接收动作。
  2. 10
    A tailing is a comprising a group of mounting filters' is a method for a firewall policy method, the mounting filter each comprises a group of filter state and an associated movement, the side of characterised, comprising:A group of information packet parameters, wherein the data packet parameter comprises an as follows data structure with a request layer association's first data packet information and a signal and second information generation, information Identification matching filter collection, wherein the matching filter centralized each filter corresponding to the information packet parameter the filter;stateAnd, which is at least filter is a matching filter is sleeved to with the operation. 10. —种用于在包括一组被安装的滤波器的防火墙引擎中执行防火墙策略的方法,所 述被安装的滤波器每个都包括一组滤波器条件和一个关联的动作,其特征在于,包括:接收一组信息包参数,所述信息包参数包括与请求层关联的第一信息包信息以及与信 息包上下文数据结构关联的第二信息包信息;识别匹配滤波器集,所述匹配滤波器集中的每个滤波器具有对应于所述信息包参数的 滤波器条件;以及,从所述匹配滤波器中的至少一个滤波器中识别所述关联的动作。
  3. 11
    A method of claim io for is composed characterised, wherein the matching filter centralized each filter with priority, associated movement and utility terminal operation from rotating and filter, and method - comprising:Which is in matching filter centralized one or more low and filter is sleeved to with the movement, till achieving terminal operation. 11. 如权利要求io所述的方法,其特征在于,所述匹配滤波器集中的每个滤波器具有优先级,并且,来自最高优先级滤波器的关联的动作是非终止动作,所述方法进一步包括:从所述匹配滤波器集中的一个或多个较低优先级滤波器中识别所述关联的动作,直到达到终止动作为止。
  4. 12
    A method of claim the IO of the characterised is made from, the matching filter collecting filter identification to shout the module, and method - comprising:Wherein the information packet parameter and came from the matching filter collecting mark of filter substrate-processing of the exhales module. 12. 如权利要求IO所述的方法,其特征在于,来自所述匹配滤波器集的滤波器识别呼出模块,所述方法进一步包括:将所述信息包参数和来自所述匹配滤波器集的滤波器的标识发送到所述呼出模块。
  5. 14
    A method of claim the IO for is composed characterised, wherein the fire the end of the operating system and method. 14. 如权利要求IO所述的方法,其特征在于,所述防火墙引擎在操作系统的用户模式中执行。
  6. 15
    A method of claim the IO for is composed characterised, wherein the fire the end of the operating system and method. 15. 如权利要求IO所述的方法,其特征在于,所述防火墙引擎在操作系统的核心模式中执行。