Method and device for filtering data stream contents

A technology of content filtering and data flow, applied to electrical components, transmission systems, etc., can solve problems such as the inability to detect network worms and the inability to cut off data flow

Inactive Publication Date: 2013-01-30
BEIJING XINWANG RUIJIE NETWORK TECH CO LTD
View PDF0 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

Therefore, the existing firewall message filtering function cannot detect network worms whose characteristic codes are distributed in multiple messages, and thus cannot stop such data streams.

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and device for filtering data stream contents
  • Method and device for filtering data stream contents
  • Method and device for filtering data stream contents

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0128] Embodiment 1. In the embodiment of the present invention, the data packet is a TCP packet. The feature code set of the network worm virus to be detected by the firewall is {HE, SHE, HIS, HERZWXY}. When the firewall is initialized, DFA is constructed based on the feature code set, as shown in Table 1. The firewall is set to cache "last come first come" packets. In the embodiment of the present invention, the firewall only needs to filter the content of each TCP packet sent by the sender, that is, the preset direction is forward. Then the firewall is tracking the TCP data flow, and the process of filtering the contents of the TCP data flow can be found in Figure 4 ,include:

[0129] Step 401: the firewall receives a SYN message, the sequence number of which is S1.

[0130] In the embodiment of the present invention, the SYN message, the SYNACK message, and the FIN message are special TCP messages, wherein the SYN message and the SYNACK message are link establishment m...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses a method and a device for filtering data stream contents, which are used for detecting network worm viruses of which the feature codes are distributed in a plurality of messages and providing the prevention capacity for firewalls. The method comprises the following steps of: acquiring a data message, and determining a stream record of the data stream of the data message and the direction of the data message; taking the recording state of a finite-state automat corresponding to the direction in the stream record as the input state of the finite-state automat, and reading characters in the data message into the finite-state automat; when the feature codes outputted by the finite-state automat are hit, filtering the data stream of the data message; and otherwise, updating the recording state of the finite-state automat corresponding to the direction in the stream record according to the corresponding output state in the finite-state automat.

Description

technical field [0001] The invention relates to the technical field of network data transmission, in particular to a method and device for filtering data stream content. Background technique [0002] The rapid development of Internet technology has not only brought unprecedented convenience to data transmission, but also brought greater convenience to the widespread spread of network worms. Network worms threaten the security of network data flow, and seriously trouble more and more network users in various fields. Therefore, it is more and more important to filter the content of network data streams and intercept data streams carrying network worms. [0003] Currently, firewall technology is used to filter the content of network data streams. Among them, the firewall organizes and manages the data flow in the form of a "linked list array", and this "linked list array" is usually called a "flow table". [0004] Taking a Transmission Control Protocol (Transmission Control ...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & AuthorityPatents(China)
IPC IPC(8): H04L29/06
Inventor丰洪才黄凯明
OwnerBEIJING XINWANG RUIJIE NETWORK TECH CO LTD