The inconsistence of firewall/VPN(Virtual Private Network) rule makes a huge maintainable cost. With development of Multinational Company, SOHO office, E-government the number of firewalls/VPN will increase rapidly. R...The inconsistence of firewall/VPN(Virtual Private Network) rule makes a huge maintainable cost. With development of Multinational Company, SOHO office, E-government the number of firewalls/VPN will increase rapidly. Rule table in stand-alone or network will be increased in geometric series accordingly. Checking the consistence of rule table manually is inadequate. A formal approach can define semantic consistence, make a theoretic foundation of intelligent management about rule tables. In this paper, a kind of formalization of host rules and network ones for auto rule-validation based on SET theory were proporsed and a rule validation scheme was defined. The analysis results show the superior performance of the methods and demonstrate its potential for the intelligent management based on rule tables.展开更多
文摘The inconsistence of firewall/VPN(Virtual Private Network) rule makes a huge maintainable cost. With development of Multinational Company, SOHO office, E-government the number of firewalls/VPN will increase rapidly. Rule table in stand-alone or network will be increased in geometric series accordingly. Checking the consistence of rule table manually is inadequate. A formal approach can define semantic consistence, make a theoretic foundation of intelligent management about rule tables. In this paper, a kind of formalization of host rules and network ones for auto rule-validation based on SET theory were proporsed and a rule validation scheme was defined. The analysis results show the superior performance of the methods and demonstrate its potential for the intelligent management based on rule tables.