...
首页> 外文期刊>Network world >The evolution of application layer firewalls
【24h】

The evolution of application layer firewalls

机译:应用层防火墙的演变

获取原文
获取原文并翻译 | 示例

摘要

First there were packet filters. Then stateful inspection firewalls; then intrusion detection. Now the latest Internet defense technology - deep packet inspection firewalls - is being touted as the best line of defense against worms that can sneak past earlier technology to wreak havoc in corporate networks. The issue with these application-layer firewalls seems to be whether they should be placed at all Internet gateways and evaluating whether they are worth the cost. By analyzing packets not just in isolation, but by reassembling and analyzing packet streams that make up individual application sessions, these application-layer firewalls can spot odd behavior by particular protocols that can signal a brand-new attack. Customers that use these products say their value is undeniable. "Now you can block [malicious traffic] as you detect it, at the edge. And the deep packet inspection [technology] can update the firewall," says Steven Goldsby CEO and founder of Integrated Computer Solutions in Montgomery, Ala., which uses Fortinet's Complete Content Inspection gear. "If it identifies an attack, then it can automatically block the IP address."
机译:首先是数据包过滤器。然后是状态检查防火墙;然后进行入侵检测。现在,最新的Internet防御技术-深度数据包检测防火墙-被誉为针对蠕虫的最佳防御线,这些蠕虫可以越过早期技术而对企业网络造成严重破坏。这些应用层防火墙的问题似乎在于是否应将它们放置在所有Internet网关上并评估它们是否值得。通过不仅隔离地分析数据包,而且通过重新组合和分析构成各个应用程序会话的数据包流,这些应用程序层防火墙可以通过特定协议发现奇怪的行为,从而发出全新的攻击信号。使用这些产品的客户表示其价值不可否认。阿拉巴马州蒙哥马利集成计算机解决方案的创始人兼首席执行官史蒂文·戈德斯比说:“现在,您可以在边缘检测到恶意流量,并进行拦截。深度数据包检测技术可以更新防火墙。” Fortinet的完整内容检查工具。 “如果识别出攻击,则可以自动阻止IP地址。”

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号