发明申请
US20060190613A1 Method, program and system for efficiently hashing packet keys into a firewall connection table
失效
方法,程序和系统,用于将数据包密钥高效地散列到防火墙连接表中
- 专利标题: Method, program and system for efficiently hashing packet keys into a firewall connection table
- 专利标题(中): 方法,程序和系统,用于将数据包密钥高效地散列到防火墙连接表中
-
申请号: US11063950申请日: 2005-02-23
-
公开(公告)号: US20060190613A1公开(公告)日: 2006-08-24
- 发明人: Everett Corl , Gordon Davis , Clark Jeffries , Steven Perrin , Hiroshi Takada , Victoria Thio
- 申请人: Everett Corl , Gordon Davis , Clark Jeffries , Steven Perrin , Hiroshi Takada , Victoria Thio
- 申请人地址: US NY ARMONK
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY ARMONK
- 主分类号: G06F15/16
- IPC分类号: G06F15/16
摘要:
A method for increasing the capacity of a connection table in a firewall accelerator by means of mapping packets in one session with some common security actions into one table entry. For each of five Network Address Translation (NAT) configurations, a hash function is specified. The hash function takes into account which of four possible arrival types a packet at a firewall accelerator may have. When different arrival types of packets in the same session are processed, two or more arrival types may have the same hash value.
公开/授权文献
信息查询