论文部分内容阅读
介绍了一种实验性的防火墙系统,与传统设计不同之处是其基于PCM模型,可以将每次网络服务请求的IP数据包的路由作为包过滤的根据。这有助于减少防火墙被欺骗的可能性,并在一定程度上避免了外部客户机使用不可信的路由。
An experimental firewall system is introduced. The difference from the traditional design is that based on the PCM model, the routing of IP data packets requested by each network service can be used as the basis for packet filtering. This helps reduce the likelihood of the firewall being spoofed and to some extent avoids the use of untrusted routes by external clients.