FIELD: information technology.
SUBSTANCE: method involves receiving packets from an external network; creating a table of connections; determining the total number of currently established connections; determining the load level of the firewall by comparing the number of established connections with a threshold; determining new and established connections based on two-way exchange of packets between a client and a server; determining connection termination based on processing ICMP messages on errors or flags in the TCP header; dynamically determining current connection timeout values based on the type of the network protocol, the connection status and load level of the firewall; changing the timestamp of processing the last packet if any packet is transmitted within a given connection or within a group of connections; terminating a connection if the timestamp of processing the last packet differs from the current time more than the timeout of said connection.
EFFECT: high reliability of established connections and providing maximum throughput with a high load.
1 tbl
Title | Year | Author | Number |
---|---|---|---|
FIREWALL OPERATING METHOD | 2018 |
|
RU2679227C1 |
METHOD OF PROTECTING COMPUTING NETWORK FROM UNAUTHORIZED SCANNING AND BLOCKING NETWORK SERVICES | 2017 |
|
RU2648949C1 |
METHOD OF OPERATING A FIREWALL | 2017 |
|
RU2667805C1 |
SYSTEM AND METHOD FOR ANALYSING INCOMING TRAFFIC FLOW | 2023 |
|
RU2812087C1 |
METHOD OF DETECTION OF COMPUTER ATTACKS IN INFORMATION AND TELECOMMUNICATION NETWORK | 2013 |
|
RU2531878C1 |
METHOD FOR PROTECTING INFORMATION AND TELECOMMUNICATION NETWORK FROM PASSIVE COMPUTER ATTACKS | 2016 |
|
RU2642403C1 |
SYSTEM FOR AGGREGATION OF NETWORK DATA IN COMPUTER NETWORKS | 2019 |
|
RU2694025C1 |
METHOD FOR PROCESSING NETWORK PACKETS TO DETECT COMPUTER ATTACKS | 2005 |
|
RU2304302C2 |
SOFTWARE AND HARDWARE COMPLEX FOR ENSURING SECURED DATA EXCHANGE BETWEEN TECHNICAL EQUIPMENT OF TERMINAL AUTOMATED SYSTEMS | 2023 |
|
RU2809234C1 |
METHOD OF PROTECTING COMPUTER NETWORKS FROM UNAUTHORISED SCANNING AND BLOCKING OF NETWORK SERVICES (VERSIONS) | 2011 |
|
RU2469390C1 |
Authors
Dates
2014-05-27—Published
2012-10-24—Filed