期刊文献+

一种解决防火墙规则冲突的混合型算法的研究

A Hybrid Algorithm to Solve Firewall Rule Conflict
下载PDF
导出
摘要 防火墙冲突检测算法是一种经典的解决防火墙过滤规则间冲突的优化算法,可有效地提高防火墙规则集的运行效率,减少规则间冲突的发生,从而节约大量的计算资源,保障网络通信的正常进行,但随着数据规模和用户数量的飞速增长,防火墙规则集也在日益扩大,原有的冲突检测算法已无法满足当前的网络通信需求,必须加以改进。论文提出了将默认规则与冲突检测算法相结合,在检测之前先执行预优化的改进策略,同时将默认规则进行解析处理,随后将其与原有规则集相合并,大大提高了防火墙的匹配效率,缩短了防火墙的处理时延。 Firewall conflict detection algorithm is a classical algorithm for the rule set of firewall filtering, which could effec-tively improve the efficiency of the firewall rule set and reduce the conflict between the rules,so as to save a lot of computing re-sources and ensure the normal operation of the network communication. However, with the rapid growth of data size and the number of users, the original conflict detection algorithm has been unable to meet the current network communication needs because the fire-wall rule set is also increasing, so the improvement is essential. This paper proposes to combine the default rules and the collision detection algorithm, and improve the pre optimization before detection. At the same time, the default rule is analyzed and combined with the original rule set, which greatly improves the matching efficiency of the firewall and shortens the processing delay of the fire-wall.
出处 《计算机与数字工程》 2017年第7期1282-1286,共5页 Computer & Digital Engineering
关键词 防火墙 动态调整 冲突检测 平均匹配次数 默认规则 firewall, dynamic tuning, conflict detection, average matching times, default rules
  • 相关文献

参考文献4

二级参考文献30

  • 1杨武,方滨兴,云晓春,张宏莉,胡铭曾.一种高性能分布式入侵检测系统的研究与实现[J].北京邮电大学学报,2004,27(4):83-86. 被引量:14
  • 2云晓春,余翔湛.基于确认度失效检测算法的研究与设计[J].北京邮电大学学报,2005,28(3):10-13. 被引量:7
  • 3中国互联网络信息中心.第29次中国互联网络发展状况统计报告[R].北京:中国互联网络信息中心.,2011.
  • 4.[EB/OL].http://pma, nlanr, net/PMA/Sites/COS, html,.
  • 5.[EB/OL].http://pma, nlanr, net/PMA/Sites/APN, html,.
  • 6Zhang Z, Ribeiro V, Moon S, Diot C. Small-time scaling behaviors of internet backbone traffic., an empirical study[C]. INFOCOM 2003.
  • 7Abry P, Veitch D. Wavelet analysis of long range dependent traffic[J]. IEEE Transactions on Information Theory, 1998,44,(1) : 2-15.
  • 8Riedi R H, Crouse M S, Ribiero V, Baraniuk R G. A multifractal wavelet model with application to TCP network traffic[J].IEEE Trans. Inform. Theory, 1999,45(3):992-1018.
  • 9Sarvotham S, Riedi R, Baraniuk R. Connection-level analysis and modeling of network traffic[R]. Tech. Rep. , ECE Dept. ,Rice Univ. , July 2001.
  • 10Wang X, Sarvotham S, Riedi R et al. Network traffic modeling using connection-level information [C]. Proceedings SPIE IT-Com, Boston, MA, August 2002.

共引文献17

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部