The invention relates to a firewall protection embedded in a bus system, which is characterized in that a bus IP core realized with FPGA logic integration technology is connected in series between the interface bus of embedded processor and the peripheral interface of the embedded processor to real-time monitor the instructions at the key ports of the embedded system, wherein, the bus IP core adopts forward regular mapping to identify normal port instructions and intercept abnormal port instructions; the bus IP core comprises three layers of organizational structure, that are, a bus adapting interface, bus firewall arranged in the firewall prevention layer, and a standard bus interface; the function of the bus firewall is realized with the special function module in the bus firewall embedded in the IP core firewall protection layer; the special function module comprises a work-mode selecting module, a through mode module, a filter mode module, a rule learning module, a bus monitor module, a signal buffer module, a state coding module, and a state detector module; the inside of the bus firewall is connected mutually with the signal relative with the bus information.