Fire wall controlling system and method based on NGN service

A control system and control method technology, applied in the field of network communication, can solve problems such as difficult maintenance, inability to select and execute packet filtering, inability to comprehensively control information, etc., and achieve the effect of preventing resource theft

Active Publication Date: 2007-01-31
HUAWEI TECH CO LTD
View PDF0 Cites 5 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

The disadvantages of [0007] static packet filtering firewall are: difficult to maintain; cannot effectively prevent hackers from spoofing attacks; does not support application layer filtering, cannot prevent data-driven attacks; cannot Provides complete control over the information flowing on the network
[0021]However, the settings of static packet filtering, state inspection and deep packet inspection in the NGN transport layer are performed by the administrator, and can only be coarse-grained security classification configured according to operational policies processing, whose existence is invisible to the NGN service layer (including session control proxy)
When a firewall provides packet filtering functions of different security levels, such as static packet filtering, dynamic packet filtering, stateful inspection, and deep packet inspection, it is impossible to dynamically select and execute packet filtering functions of different security levels according to user needs and session types

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Fire wall controlling system and method based on NGN service
  • Fire wall controlling system and method based on NGN service

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0055] In the NGN service layer architecture, the session control proxy function is an essential component, such as the P-CSCF (Proxy Call Session Control Function) in the IMS (Multimedia Service Subsystem), which is essentially an application proxy and a multimedia session The first contact point of the business is to perform user authentication, application protocol analysis and proxy, and NAPT (Network Address and Port Translator) at the application layer. In the NGN transport layer architecture, the firewall function based on packet filtering is an essential security component, including static packet filtering, dynamic packet filtering, state inspection and deep packet inspection functions, and is usually deployed at the edge of the network to protect internal components of the network. under attack.

[0056] Therefore, the present invention provides a firewall dynamic control system and method supporting NGN service security level. Through the cooperative work between t...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides an NGN service-based firewall control system and method. And its kernel comprises: first, application layer agent module in service control equipment analyzes application layer signaling and makes safe detection on signaling flow, determining safety grade request information of service media flow and providing the request information for policy making functional entity; then the policy making functional entity determines corresponding media flow safety grade control information according to the request information and the stored policy information and providing the control information for network boundary equipment; and finally, the packet filtration-based firewall functional module in the network boundary equipment makes safe detection on the service media flow according to the control information. Therefore, it can prevent resource embezzlement and IP address counterfeiting and put an end to service and advanced application invasion and other network attacks.

Description

technical field [0001] The invention relates to the technical field of network communication, in particular to a firewall control system and method based on NGN services. Background technique [0002] NGN (Next Generation Network) realizes the separation of the service layer and the transport layer. The transport layer is based on packet and optical technologies, and the service layer provides rich multimedia services. Because NGN network is based on IP grouping technology, therefore, solving the security and service quality problems of NGN business will be paid much attention to. As the most important and most widely used network security technology, the firewall function will continue to be used in solving the security problems of NGN services. [0003] At present, firewall products are mainly divided into two types: packet filtering firewall and proxy firewall. Among them, the packet filtering firewall works at the transport layer, and the proxy firewall works at the ap...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L12/56
CPCH04L63/029H04L63/0218H04L29/08576H04L63/0281H04L67/14
Inventor 刘恩慧
Owner HUAWEI TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products