摘要
状态防火墙是一种新型防火墙,而传统防火墙决策图(FDD)构造算法并不适用于状态防火墙的规则集比对.本文在FDD基础上,提出一种状态防火墙决策图(SFDD)构造算法,将规则集转化成图形化的等价的SFDD,用于状态防火墙规则集比对.理论分析和仿真实验结果表明,利用SFDD构造算法进行比对,能有效检测出规则集之间的全部不同点;当状态防火墙的状态部分规则和无状态部分规则条目数量均达到3 000时,比对过程所耗费的平均时间不超过2s.
The stateful firewall is a new type of firewall,and the traditional firewall decision diagrams (FDD)construction algorithm does not apply to stateful firewall rule set.This paper presented a stateful firewall decision diagrams (SFDD)construction algorithm,which transforms the stateful firewall ACLs in-to equivalent stateful firewall decision diagrams,and is applied to the stateful firewall rule set comparison. Theoretical analysis and simulation results have shown that the method can effectively detect all the differ-ences between the rule sets.And when the number of rules for both the stateful and stateless section is 3000,the time cost is less than 2 s.
出处
《湖南大学学报(自然科学版)》
EI
CAS
CSCD
北大核心
2014年第10期103-107,共5页
Journal of Hunan University:Natural Sciences
基金
国家自然科学基金资助项目(61272546
61472131
61070194)
关键词
网络安全
防火墙规则
访问控制
network security
firewall rules
access control