摘要
从研究网络安全设备内策略冲突检测方法入手,针对当前设备内策略冲突检测算法不具有扩展性的缺点,采用规范化和离散化技术,将策略域的属性数据统一映射到实数区间;通过定义实数区间的关系运算判断策略域之间的关系;在此基础上设计了一种可扩展的网络安全设备内冲突检测算法;该算法通过规则过滤处理,提高了安全策略冲突检测算法的执行效率。实验验证表明该算法正确高效,具有实用价值。
This paper researched the intra network security device policy conflict detection method firstly.To aim at the lack of extendibility of most intra network security device policy conflict detection algorithms,used the standardization and discretization technologies,which mapped the attribute data of policy fields to the real number interval.Through defining the relation operation in real number interval,determined the relation between policy fields.Based on it,designed an extensible intra network security device policy conflict detection algorithm.Applying the rule filtering,improved the execute efficiency of the algorithm.The experimentation results show that the algorithm is correct,efficient and have practical value.
出处
《计算机应用研究》
CSCD
北大核心
2010年第4期1484-1488,共5页
Application Research of Computers
基金
国家"863"计划资助项目(2006AA701416
2006AA01Z457)
关键词
网络安全设备策略
设备内冲突检测
可扩展
规范化
离散化
规则过滤
network security device policy
intra device conflict detection
extendible
standardization
discretization
rule filtering