首页> 外文会议> >A formal model of network policy analysis
【24h】

A formal model of network policy analysis

机译:网络策略分析的正式模型

获取原文
获取原文并翻译 | 示例

摘要

The complexity of network topology together with heterogeneity of network services make the network configuration a hard task, even for skilled and experienced administrators. In order to reduce the complexity of the network configuration, administrators have leveraged network policies, introducing hence new possibility of error. Indeed, erroneous and unexpected network behaviour (e.g., security flaws) can derive from the wrong network policy definition, but also from the possible anomalies among policies of different domains. This paper presents a formal model for detecting inter- and intra-domain policy anomalies. Policy anomalies allow administrators to identify all the network behaviours they consider erroneous or to be monitored. To validate the generality of the proposed solution, the model has been applied to three policy domains (packet filtering, communication protection and service function chaining) and the impact of an anomaly detection analysis was tested in different sized networks.
机译:网络拓扑的复杂性以及网络服务的异构性使网络配置成为一项艰巨的任务,即使对于熟练且经验丰富的管理员而言。为了降低网络配置的复杂性,管理员利用了网络策略,因此引入了新的错误可能性。实际上,错误和意外的网络行为(例如,安全漏洞)可能源自错误的网络策略定义,也可能源自不同域的策略之间的可能异常。本文提出了一种用于检测域间和域内策略异常的正式模型。通过策略异常,管理员可以识别他们认为错误或受到监视的所有网络行为。为了验证所提出解决方案的通用性,该模型已应用于三个策略域(数据包过滤,通信保护和服务功能链),并在不同规模的网络中测试了异常检测分析的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号