Invention Grant
- Patent Title: Data detecting method and apparatus for firewall
- Patent Title (中): 防火墙数据检测方法及装置
-
Application No.: US14305723Application Date: 2014-06-16
-
Publication No.: US09398027B2Publication Date: 2016-07-19
- Inventor: Shiguang Li , Wu Jiang , Zhihui Xue , Linghong Ruan
- Applicant: Huawei Technologies Co., Ltd.
- Applicant Address: CN Shenzhen
- Assignee: Huawei Technologies Co., Ltd.
- Current Assignee: Huawei Technologies Co., Ltd.
- Current Assignee Address: CN Shenzhen
- Agency: Conley Rose, P.C.
- Agent Grant Rodolph
- Priority: CN201110459872 20111231; CN201210045928 20120227
- Main IPC: H04L29/00
- IPC: H04L29/00 ; H04L29/06 ; H04L12/26 ; H04L12/24

Abstract:
A data detecting method and apparatus for a firewall device connected with a network to identify security threat in the data, where the method is implemented by a fast forwarder in the firewall device and includes: the fast forwarder receives application data; obtains application information in the received application data; determines an application protocol type corresponding to the application data according to the application information and an application identifying table; queries a configuration item for threat detection according to the application protocol type to determine whether the application data requires threat detection; and if the application data does not require threat detection, forwarding the application data. The data detecting method avoids a problem that performance of a firewall is degraded because all application data is sent to a detecting processor in the firewall device for detection, thereby improving an performance of the firewall device.
Public/Granted literature
- US20140298466A1 Data Detecting Method and Apparatus for Firewall Public/Granted day:2014-10-02
Information query