期刊文献+

一种基于切割映射的规则冲突消除算法 被引量:4

A Filter Conflicts Resolving Algorithm Based on Cutting Mapping
下载PDF
导出
摘要 防火墙规则冲突不仅使规则集变得难于管理,而且会影响报文分类的效率.现有的规则冲突消除算法不能完全消除冲突.针对这一情况,从计算几何角度对规则冲突进行了分析,提出了一种基于切割映射的冲突消除算法.该算法对规则冲突进行了详细的分类,并根据不同的类型消除冲突.算法以两条冲突规则为基本处理对象,在其冲突消除过程中,顺序切割优先级较低的规则的每一维分量.理论分析和测试表明,算法达到了只需增加少量规则即能彻底消除冲突的目的. Filter conflicts resolving is an important issue for packet classification and network management. On the one hand, to reduce the time spent on packet classlfication, a certain algorithm for resolving filter conflicts should be applied to eliminate all filter conflicts during the preprocessing phase. On the other hand,because of the complexity of firewall filters, when firewall administrators add a filter, the newly added filter may conflict with existing ones. This not only makes filter datahases difficult to manage, but also may lead to security vuluerabilities. Thus a certain algorithm for resolving filter conflicts should also be applied to eliminate all filter conflicts. Several algorithms for resolving filter conflicts have already been proposed but most of them cannot eliminate filter conflicts completely and set restrictions on filters. This paper analyses filter conflicts from the perspective of computational geometry and presents a filter conflicts resolving algorithm based on cutting mapping. The algorithm resolves filter conflicts according to the classification of conflicts. It treats two filters as the basic processed object and sequentially cuts every dimension of the filters that have lower priority. This paper proves the algorithm and experiments verify its good performance.
作者 李林 卢显良
出处 《电子学报》 EI CAS CSCD 北大核心 2008年第2期408-412,共5页 Acta Electronica Sinica
基金 信息产业部生产发展基金(No.2002[546])
关键词 规则冲突 冲突消除 切割映射 计算几何 冲突分类 filter conflicts resolving conflicts cutting mapping computational geometry classification of conflicts
  • 相关文献

参考文献8

  • 1Ehab Al-Shaer, Hazem Hamed. Taxonomy of conflicts in network security policies [ J ]. IEEE Communications Magazine, 2006,44(3) : 134 - 141.
  • 2Ehab Al-Shaer, Hazem Hamed. Discovery of policy anomalies in distributed firewalls [ A]. IEEE INFOCOM 2004 [ C ]. San Diego: IEEE,2004.2605 - 2616.
  • 3Ehab Al-Shaer,Hazem Hamed. Conflict classification and analysis of distributed firewall policies[ J]. Selected Areas in Communications, 2005 ,23(10) :2069 - 2084.
  • 4Adiseshu Hari, Subhash Suri. Detecting and resolving packet filter conflicts[ A]. IEEE INFOCOM 2000[ C]. Tel Aviv: IEEE,2000.1203 - 1212.
  • 5Haibin Lu, Sartaj Sahni. Conflict detection and resolution in two-dimensional prefix router tables[ J]. IEEE/ACM Transactions on Networking,2005,13(6) : 1353 - 1363.
  • 6田大新,刘衍珩,李永丽,唐怡.数据包过滤规则的快速匹配算法和冲突检测[J].计算机研究与发展,2005,42(7):1128-1135. 被引量:14
  • 7杜德超,姚庆栋.多维过滤规则无冲突的高速分组分类算法[J].电子学报,2002,30(11):1676-1680. 被引量:6
  • 8Xuehong Sun, Sartaj K. Sahni. Packet classification consuming amount of memory[J].IEEE Ttansactions on Networking,2005,13(5) : 1135 - 1144.

二级参考文献28

  • 1[1]T V Lakshman,D Stiliadis.Hight-speed policy-based packet forwarding using efficient multi-dimensional range matching[A].Proc.of ACM Sigcomm[C].Vancouver,Canada:1998.101-202.
  • 2[2]M Waldvogel,G Varghese,J Turner,B Plattner.Scalable hight speed IP routing lookups[A].Proc. of Sigcomm[C].Cannes,France,1997.25-35.
  • 3[3]V Srinivasan,S Suri,G Varghese.Packet classification using turple space search[A].Proc. of Sigcomm[C].Cambridge,Massachusetts,1999.135-1466.
  • 4[4]A Hari,S Suri,G Parulkar.Detecting and resolving packet filter conflicts[J].Porc. of IEEE INFOCOMM,2000.1203-1213.
  • 5[5]P Warkhede,S Suri,G Varghese.Fast packet classification for two-dimensional conflict-freee filters[J].IEEE INFOCOM,2001.1434-1443.
  • 6[6]P Gupta,N McKeown.Packet classification on multiple fields[J].ACM Computer Review,1999,29(4):146-160.
  • 7[7]V Srinivasan,G Varghese,S Suri,M Waldvogel.Fast and scalable layer four switching[A].Proc.ACM Sigcomm[C].Vancouver,Canada,1998.203-214.
  • 8[8]Anthony J McAuley,Paul Francis.Fast routing table lookup using CAMs[J].IEEE INFOCOM,1993,3:1382-1391.
  • 9[9]P Gupta,N McKeown.Algorithms for packet classification[J].IEEE Network,2001,4:24-32.
  • 10[10]http://nic.merit.edu/impa[DB/OL].2001,8.

共引文献18

同被引文献20

引证文献4

二级引证文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部