States collection and rules collection together enable efficient access control . among options of different content filtering methods , the state machine - based plan is selected , which is more appropriate for hardware design . and based on this , the concept of unit filter module - servo is presented , and the implementation of the servos " array enables parallel filtering and enhanced the performance of content filter module 此外,还进一步引入了cache的设计思想,提出了状态表结构,状态表和规则表的有机配合,实现了高效的访问控制功能;在内容过滤的众多选择中,针对硬件设计的特点,确立了基于状态机的实现方案,并提出了单元过滤模块?伺服器的概念,通过伺服器阵列技术的引入,使得过滤可以并发执行,提高了内容过滤模块的处理能力。
Single packet filter technology , with its flaws , cannot provide perfect security protection ; intrusion detection , as an active defense system , is a crucial supplementary to the packet technology and work as a second line of defense ; content filter supplies the gap of the information content protection that two former technologies leave and form the last barrier for security protection 单纯的包过滤技术由于其自身的缺陷而不能提供完全的安全保护。入侵检测作为一种主动防御技术,是包过滤的重要补充,起到了第二道防线的作用。内容过滤弥补了前两种技术在信息内容防范方面的不足,形成了安全防护的最后一道屏障。
In this paper , we firstly analyze system structures and working principles and functions of user management and controlling system . secondly , we research some key technologies of network controlling deeply , such as packet filtering technology and content filtering technology . finally , we design and implement the management and controlling software system of network controller and test it 本文首先分析了用户管理控制系统的系统结构、工作原理和功能,然后深入研究了上网控制的若干关键技术,如包过滤技术和内容过滤技术,最后设计和实现了上网控制器的管理控制软件系统,并对其进行了功能测试。