摘要 |
PURPOSE: A manager customized dynamic firewall using an object module is provided to enable a manager to express a desired security policy precisely and intentionally by using the object module and defining the relationship between the modules, and to meet a specific situation fast and voluntarily by using an operation object module. CONSTITUTION: A tag(4) is formed by capping a capsule(3) to a packet coming in a firewall computer. If the packet passes the specific object module after the operation module, the tag carries out a specific operation. The processed packet capped by the capsule flows by following a policy object module fixed by the intention of the manager. Each policy object has a result, and the packet flows to different object according to the result. Thus, a different security policy is fixed to each packet.
|