作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (11): 169-171.

• 安全技术 • 上一篇    下一篇

下一代应用层防火墙性能及其测试

刘晓红,纪越峰   

  1. 北京邮电大学电信系,北京 100876
  • 出版日期:2006-06-05 发布日期:2006-06-05

Review of Next Application-aware Firewall Performance and Evaluation

LIU Xiaohong,JI Yuefeng   

  1. Dept. of Telecommunications, Beijing University of Posts & Telecommunication, Beijing 100876
  • Online:2006-06-05 Published:2006-06-05

摘要: 针对Internet 上越来越复杂的网络攻击,防火墙已经由过去单纯的底层包过滤型防护墙向下一代的应用层防火墙转变,从而对下一代网络安全测试也提出了新的要求。在进行网络安全评估时,需要采用新的状态流,同时还必须综合考虑防火墙的具体设置。该文对下一代应用层防火墙的发展现状及趋势、测试技术及方法进行了探讨,为进一步探索新的应用层防火墙测试技术提供基础依据。

关键词: 应用层防火墙;性能测试;Internet 网络攻击

Abstract: Network security devices are becoming smarter, turning from basic packet-filtering to application-awareness, in order to mitigate newapplication attacks on the Internet. Traditional vendor performance specifications are inadequate now, forcing vendors and network designers toadopt new test methods for performance evaluation and benchmarking. This paper gives a review and research on the next firewall development andevaluation, and puts forward the future research direction.

Key words: Application-aware firewall; Performance evaluation; Internet attacks