期刊文献+

一种防火墙规则冲突检测算法 被引量:9

Firewall rule conflict discovery algorithm
下载PDF
导出
摘要 在入侵检测系统和状态检测防火墙等应用中,规则冲突检测及冲突解析算法是影响安全性及服务质量的关键。首先对防火墙过滤规则之间的关系进行了建模和分类。然后在过滤规则关系分类的基础上提出了一种冲突检测算法。该算法能够自动检测、发现规则冲突和潜在的问题,并且能够对防火墙过滤规则进行无冲突的插入、删除和修改。实现该算法的工具软件能够显著简化防火墙策略的管理和消除防火墙的规则冲突。 In applications of intrusion detection and stateful filtering,conflict discovery and resolution are key issues affecting security and QoS.The classification of rule relations is described.Based on the classification,a new firewall conflict discovery algorithm is proposed,which provides automatic revelation of firewall filtering rule conflicts and potential problems,and provides conflict-free insertion,removal and modification of rules.This algorithm is implemented in a tool,which significantly simplifies the management of firewall policy and eliminates rule conflicts.
出处 《计算机工程与应用》 CSCD 北大核心 2007年第15期111-113,117,共4页 Computer Engineering and Applications
基金 国家自然科学基金(the National Natural Science Foundation of China under Grant No.60403027) 。
关键词 防火墙 规则分类 规则冲突 冲突检测 firewall rule classification rule conflict conflict discovery
  • 相关文献

参考文献7

  • 1Eppstein D,Muthukrishnan S.Intemet packet filter management and rectangle geometry[C]//Proceedings of 12th Annual ACM-SIAM Symposium on Discrete Algorithms(SODA).Washington D C:ACM Press,2001:827-835.
  • 2Hari B,Suri S,Parulkar G.Detecting and resolving packet filter conflicts[C]//Proceedings of IEEE INFOCOM'00.Tel Aviv,Israel:IEEE Press,2000:1203-1212.
  • 3Lupu E,Sloman M.Conflict analysis for management policies[C]//Stadler R,Lazar A,Saraco R.Proceedings of IFIP/IEEE International Symposium on Integrated Network Management (IM'97).San-Diego:IEEE Press,1997:430-443.
  • 4Fu Z,Wu F,Huang H,et al.IPSec/VPN security policy:correctness,conflict detection and resolution[C]//Proceedings of Policy'2001 Workshop,2001:39-56.
  • 5Eronen P,Zitting J.An expert system for analyzing firewall rules[C]//Proceedings of 6th Nordic Workshop on Secure IT-Systems(NordSec 2001),Copenhagen,Denmark:Technical University of Denmark,2001:100-107.
  • 6Chapman D,Zwicky E.Building Internet firewalls[M].2nd.[S.l.]:Orielly & Associates Inc,2000.
  • 7Cheswick W,Belovin S.Firewalls and Internet security[M].[S.l.]:Addison Wesley,1995.

同被引文献68

引证文献9

二级引证文献29

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部