发明名称 System, device and method for rapid packet filtering and processing
摘要 A system, a device and a method for accelerating packet filtration by supplementing a firewall with a pre-filtering module. The pre-filtering module performs a limited set of actions with regard to the packets, according to whether the packets are received from a connection which has been previously permitted by the firewall. If the packets are received from such a permitted connection, then the pre-filtering module forwards the packets to their destination, optionally performing one or more actions on the packets. Otherwise, the packets are forwarded to the firewall for handling. Preferably, once the firewall has transferred responsibility for the connection to the pre-filtering module, or "off-loaded" the connection, the firewall does not receive further packets from this connection until a timeout occurs for the connection, or a packet is received with particular session-control field values, such that the connection is closed. Optionally and preferably, the pre-filtering module is implemented as hardware.
申请公布号 US6496935(B1) 申请公布日期 2002.12.17
申请号 US20000517276 申请日期 2000.03.02
申请人 CHECK POINT SOFTWARE TECHNOLOGIES LTD 发明人 FINK GONEN;HARUSH AMIR
分类号 H04L12/66;H04L29/06;(IPC1-7):G06F11/30;H01S3/097 主分类号 H04L12/66
代理机构 代理人
主权项
地址