期刊文献+

一种基于SFDD的状态防火墙规则集比对方法 被引量:5

A New Approach to Compare Stateful Firewall Rule Set Based on SFDD
下载PDF
导出
摘要 状态防火墙是一种新型防火墙,而传统防火墙决策图(FDD)构造算法并不适用于状态防火墙的规则集比对.本文在FDD基础上,提出一种状态防火墙决策图(SFDD)构造算法,将规则集转化成图形化的等价的SFDD,用于状态防火墙规则集比对.理论分析和仿真实验结果表明,利用SFDD构造算法进行比对,能有效检测出规则集之间的全部不同点;当状态防火墙的状态部分规则和无状态部分规则条目数量均达到3 000时,比对过程所耗费的平均时间不超过2s. The stateful firewall is a new type of firewall,and the traditional firewall decision diagrams (FDD)construction algorithm does not apply to stateful firewall rule set.This paper presented a stateful firewall decision diagrams (SFDD)construction algorithm,which transforms the stateful firewall ACLs in-to equivalent stateful firewall decision diagrams,and is applied to the stateful firewall rule set comparison. Theoretical analysis and simulation results have shown that the method can effectively detect all the differ-ences between the rule sets.And when the number of rules for both the stateful and stateless section is 3000,the time cost is less than 2 s.
出处 《湖南大学学报(自然科学版)》 EI CAS CSCD 北大核心 2014年第10期103-107,共5页 Journal of Hunan University:Natural Sciences
基金 国家自然科学基金资助项目(61272546 61472131 61070194)
关键词 网络安全 防火墙规则 访问控制 network security firewall rules access control
  • 相关文献

参考文献9

  • 1李林,卢显良,李泽平,聂晓文,彭永祥,李梁.一种适用于Diverse Firewall Design的规则集比较算法[J].四川大学学报(工程科学版),2009,41(5):160-164. 被引量:2
  • 2LIU A X, GOUDA M G. Diverse firewall desigrt[J]. IEEE Transactions on Parallel and Distributed Systems, 2008, 19 (9): 1237-1251.
  • 3LIU A X, GOUDA M G. Complete redundancy removal for packet classifiers in TCAMs [J]. IEEE Transactions on Paral- lel and Distributed Systems, 2010, 21(4): 424-437.
  • 4LIU A X. Firewall policy change-impact analysis [J]. ACM Transactions on Internet Technology, 2012(3) : 2122-2128.
  • 5LIU A X, GOUDA M G. Complete redundancy detection in firewalls[C]//Proceedings of 19th Annual IFIP Conference on Data and Applications Security. New York: IEEE, 2005:196 -209.
  • 6L1U A X, GOUDA M G. Firewall policy queries l-J]. IEEE Transactions on Parallel and Distributed Systems, 2009, 20 (6): 766-777.
  • 7GOUDA M G, LIU A X. Firewall design: consistency, com- pleteness and compactness[C]//Proceedings of the 24th IEEE International Conference on Distributed Computing Systems (ICDCS). New York: IEEE, 2004: 320-327.
  • 8GOUDA M G, LIU A X. A model of stateful firewalls and its properties[C]//Proceedings of the IEEE International Confer- ence on Dependable Systems and Networks. New York: IEEE, 2005:128-137.
  • 9LAUNAY A. High level firewall language[EB/OL]//[2012- 10-28] http://www, hill. org.

二级参考文献1

共引文献1

同被引文献23

  • 1李林,卢显良,李泽平,聂晓文,彭永祥,李梁.一种适用于Diverse Firewall Design的规则集比较算法[J].四川大学学报(工程科学版),2009,41(5):160-164. 被引量:2
  • 2汤昂昂,陈永波,姬东鸿.一种分布式防火墙规则有效性检测算法[J].微电子学与计算机,2015,32(2):5-9. 被引量:1
  • 3王卫平,陈文惠,朱卫未,陈华平,杨杰.分布式防火墙策略配置错误的分析与检测[J].中国科学院研究生院学报,2007,24(2):257-265. 被引量:4
  • 4Liu A X, Gouda M G. Diverse firewall design[J]. Par- allel and Distributed Systems, IEEE Transactions on, 2008,19(9) : 1237-1251.
  • 5Liu A X, Gouda M G. Complete redundancy removal for packet classifiers in tcarns[J]. Parallel and Distributed Systems, IEEE Transactions on, 2010,21(4) : 424-437.
  • 6Liu A X. Firewall policy change-impact analysis[J]. ACM Transactions on Internet Technology (TOIT), 2012,11(4) : 15.
  • 7Salah K, Qahtan A. Implementation and experimental performance evaluation of a hybrid interrupt-handling scheme[J]. Computer Communications, 2009,32 (1) : 179-188.
  • 8Zhang J, Li T. Based on the Queuing Model of CAN Bus Simulation and Application[C]//Proceedings of The Eighth International Conference on Bio-Inspired Computing.- Theories and Applications (BIC-TA), 2013,2013 : 631-639.
  • 9Chen F, Liu A X, Hwang J, et al. First step towards automatic correction of firewall policy faults[J]. ACM Transactions on Autonomous and Adaptive Systems (TAlkS), 2012, ? (2) : 27.
  • 10Launay A. High level firewall language[J/OL]. 2012- 10-28. http://www, hill. rog, 2003.

引证文献5

二级引证文献7

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部