期刊文献+

一种性能优化的防火墙规则匹配算法 被引量:3

Modified firewall rules matching algorithm
下载PDF
导出
摘要 设计了一种防火墙规则匹配算法,该算法基于分治思想将规则集按照协议类型分割为多个子集,并根据规则之间的关系,将各子集分为无序组和有序组,通过设计哈希函数和索引算法对两组规则进行分别匹配。分析表明,该算法的效率远优于同类算法,大大提高了防火墙的工作性能。 This paper designed a firewall rule matching algorithm based on the idea of divide-and-conquer.In accordance with the protocol type,it divided the rules set into multiple sub-sets.Then,accordance with the relationship between two rules,each sub-set was divided into two groups: disordered group and sequence group.Furthermore,this paper designed hash function to match rules in disorded group,while it proposed indexing algorithm to match rules in the sequence group.The analysis shows that the efficiency of this algorithm is much better than similar algorithms,and it greatly improves the performance of the firewall.
作者 李中 李晓
出处 《计算机应用研究》 CSCD 北大核心 2013年第4期1205-1207,共3页 Application Research of Computers
关键词 防火墙规则 匹配算法 分治思想 索引 firewall rule matching algorithm idea of divide-and-conquer indexing
  • 相关文献

参考文献9

  • 1LIU A X, MEINERS C R, TORNG E. TCAM Razor: a systematic approach towards minimizing packet classifiers in TCAMs[ J]. IIZIZE/ ACM Trans on Networking,2010,18(2) : 266-275.
  • 2MEINERS C R, LIU A X, TORNG E. Topological transformation ap- proaches to TCAM-based packet classification [ J ]. IEEE/ACM Yrans on Networking,2011,19( 1 ) : 237-250.
  • 3LU H, SAHNI S. O(logW) multidimensional packet classification [J]. IEEE/ACM Trans on Networking,2007,15(2) : 462-472.
  • 4KIM H, KIM S, KIM M H. Scalable packet classification through mlebase partitioning using the maximum entropy hashing[ J ]. I EEE/ AGM Trans on Networking,2009,17(6) :1926-1935.
  • 5GUPTA P, McKEOWN N. Packet classification using hierarchical in- telligent cuttings[ J]. IEEE Micro,2000,20( 1 ) :34-41.
  • 6SINGH S, BABOESCU F, VARGHESE G, et al. Packet classifica- tion using multidimensional cuttings[ C ]//Proc of Conference on Ap- plications Technologies, Architectures, and Protocols for Computer Communications. New York : ACM Press,2003:213-224.
  • 7TAYLOR D, TURNER J. Scalable packet classification using distrib- uted crossproducing[ J ]. IEEE Micro ,2006,90 ( 5 ) :49-60.
  • 8PANKAJ G, ICKM N. Packet classification on muhiple fields [ J ]. Computer Communication Review,1999,29(4) : 47-60.
  • 9VAMANAN B, VOSKUILEN G, VIJAYKUMAR T N. Optimizing packet classification for memory and throughput [ J ]. Computer Communication Review ,2010,40 (4) : 207-218.

同被引文献35

  • 1程勇,秦祖福,傅建明.有序二叉决策图在防火墙规则库设计中的应用[J].武汉大学学报(理学版),2006,52(1):77-80. 被引量:4
  • 2陈娟,陈崚.求解多重序列比对问题的蚁群算法[J].计算机应用研究,2007,24(1):25-30. 被引量:3
  • 3ONF. Software-Defined Networking: the New Norm for Networks[EB/OL]. [2015-05-04]. http://wenku.baidu.com/view/74cbdflac281e53a5802ffa7.html.
  • 4SHIN Seungwon, PHIL P, VINOD Y. FRESCO: Modular Composable Security Services for Software-Defined Networks[C]//Proceedings of Network and Distributed Security Symposium. San Diego: Internet Society , 2013: 135-139.
  • 5KANG Nanxi, REXFORD R, WALKER D. Policy Transformation in Software Defined Networks[C]// ACM SIGCOMM Computer Communication Review-Special october issue. New York: ACM Special Interest Group on Data Communication, 2012(12): 309-310.
  • 6YOUNA J, JAMES B D. CRiBAC: Community-centric role interaction based access control model Computers Security[J]. computer & secturity, 2012, 31(4): 497-523.
  • 7KRAUTSEVICH L, LAZOUSKI A, MARTINELLI F. Risk-aware Usage Decision Making in Highly Dynamic Systems[C]// The Fifth Internet Monitoring and Protection. Barcelona, Spain: IEEE press, 2010: 29-34.
  • 8秦拯, 厉怡君, 欧露. SFDD算法的设计及其在状态防火墙规则集比对的应用[D]. 长沙: 湖南大学, 2013.
  • 9李林,卢显良.一种基于切割映射的规则冲突消除算法[J].电子学报,2008,36(2):408-412. 被引量:4
  • 10陈新一.三分搜索法在数组排序中的应用[J].科学技术与工程,2008,8(24):6612-6613. 被引量:1

引证文献3

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部