期刊文献+

离线数据驱动的防火墙性能优化方法 被引量:1

Firewall performance optimization method driven by offline data
下载PDF
导出
摘要 为减少防火墙规则平均匹配次数和处理时间,提升规则匹配的准确率,提出一种由离线数据驱动的防火墙性能优化方法。统计网络日志中一段时间内规则匹配频率,动态调整规则集合中的规则匹配顺序;将每个规则作为一个类,通过给定的网络日志信息作为训练数据集离线创建决策树规则分类器;分类器对实时到来的数据包进行规则预测,预测成功则按照匹配的规则类动作执行,不成功则按照调整后的规则列表匹配。通过定时更新训练数据集,实时动态地生成新的分类器,调整规则序号。仿真结果表明,相对于其它防火墙,该方法在规则匹配的效率方面有很大提升,规则匹配总次数和处理总时间明显减少,防火墙性能显著提升。 To reduce average matching times,total processing time and improve matching accuracy of firewall rules,a method driven by offline flow traces data was presented.The matching frequency of each rule in a certain period time was calculated and each rule's matching label was dynamically reordered.Each rule was regarded as a class and a decision tree classifier was created using offline internet trace and log files.The classifier predicted which rule was most likely going to be matched for each coming packet.If correct,the corresponding action of the matched rule was taken,otherwise,the packet was matched by reordered rules one by one.At the same time,through updating the training data,the classifier and rules' matching order were updated dynamically.Experimental results show that compared to other firewalls,the enhanced firewall has improvements in the efficiency of filtering packets.The performance of the optimized firewall is improved significantly while rules' total matching times and total processing time are reduced apparently.
作者 张林 黄梦醒
出处 《计算机工程与设计》 北大核心 2016年第8期1990-1994,共5页 Computer Engineering and Design
基金 国家自然科学基金项目(61462022) 国家科技支撑计划基金项目(2011BAG02B07)
关键词 分类 防火墙策略 规则 数据驱动 性能优化 classification firewall policy rules data driven performance optimization
  • 相关文献

参考文献12

  • 1Scarfone K A,Hoffman P.SP 800-41Rev.1.Guidelines on firewalls and firewall policy[S].Nist Special Publication,2009.
  • 2Liu Z,Chen P.Improved method of packet filtering[C]//Proc International Conference of Web Information Systems and Applications,2009:294-296.
  • 3Trabelsi Z,Sayed HE,Zeidan S.Firewall packet matching optimization using network traffic behavior and packet matching statistics[C]//Third International Conference on Communications and Networking.IEEE,2012:1-7.
  • 4Vasu A,Ganesh A,Ayyappan P,et al.Improving firewall performance by eliminating redundancies in access control lists[J].International Journal of Computer Networks,2014,6(5):92-107.
  • 5Pault G,Pothnal A,Mandalt C,et al.Design and implementation of packet filter firewall using binary decision diagram[C]//Proc the IEEE Students’Technology Symposium,2011:17-22.
  • 6El-Atawy A,Al-Shaer E,Tran T,et al.Adaptive early packet filtering for defending firewalls against DOS attacks[C]//INFOCOM.IEEE,2009:2437-2445.
  • 7Mothersole I,Reed M J.Optimising rule order for a packet filtering firewall[C]//Conference on Network and Information Systems Security.IEEE,2011:1-6.
  • 8Trabelsi Z,Zeidan S.Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvement[C]//IEEE International Conference on Communications.IEEE,2012:1074-1078.
  • 9Saboori E,Parsazad S,Sanatkhani Y.Automatic firewall rules generator for anomaly detection systems with Apriori algorithm[C]//International Conference on Advanced Computer Theory&Engineering,2012:V6-57-V6-60.
  • 10Wang W,Chen H,Chen J,et al.Firewall rule ordering based on statistical model[C]//International Conference on Computer Engineering&Technology.IEEE,2009:185-188.

同被引文献13

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部