基于NP芯片的ACL防攻击研究与实现  被引量:1

Research and implementation of ACL defence based on network processor chip

在线阅读下载全文

作  者:王嘉楠 吴军平[2] WANG Jianan;WU Junping(School of Fiberhome,Wuhan Institute of Posts and Telecommunications,Wuhan 430074,China;Fiberhome Communication Technology Co.,Ltd.,Wuhan 430073,China)

机构地区:[1]武汉邮电科学研究院烽火学院,湖北武汉430074 [2]烽火通信科技股份有限公司,湖北武汉430073

出  处:《电子设计工程》2021年第20期152-155,160,共5页Electronic Design Engineering

摘  要:为了实现转发过程中包过滤的功能,在三层交换机的接口上绑定一张访问控制列表(Access Control Lists,ACL),根据特定匹配规则执行通过或丢弃等预先设定的操作。基于硬件拦截恶意报文的目的,采用了基于NP芯片的ACL包过滤方案,从操作平台数据平面对象(FOS Data Plane Object,FDPO)中获取数据,映射在驱动数据平面对象(Device Data Plane Object,DDPO)并下发到接口,通过在接口处制定相应的流策略模板对流量快速响应,使用流分类的方法控制流量,实现拦截96%以上攻击报文的功能,有效缓解CPU处理压力。In order to realize the function of packet filtering in the forwarding process,an Access Control List(ACL)is bound to the interface of the layer 3 switch,and predetermined actions such as passing or discarding are executed according to specific matching rules.For the purpose of intercepting malicious messages based on hardware,the ACL packet filtering scheme based on NP chip is adopted.By obtaining data from the FOS Data Plane Object(FDPO)in the operating platform,it is mapped to the Driver Data Plane Object(DDPO)is then issued to the interface,and the corresponding flow policy template is formulated at the interface to quickly respond to the flow,and the flow classification method is used to control the flow,achieving the function of intercepting more than 96%of attack packets and effectively alleviating the CPU deal with stress.

关 键 词:访问控制列表 包过滤 NP芯片 防攻击 

分 类 号:TN919.3[电子电信—通信与信息系统]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象