首页> 外文会议>2011 7th International Conference on Network and Service Management >On synthesizing distributed firewall configurations considering risk, usability and cost constraints
【24h】

On synthesizing distributed firewall configurations considering risk, usability and cost constraints

机译:在综合考虑风险,可用性和成本约束的分布式防火墙配置时

获取原文

摘要

Firewalls are the most deployed security devices in computer networks. Nevertheless, designing and configuring distributed firewalls, which include determining access control rules and device placement in the network, is still a significantly complex task as it requires balancing between connectivity requirements and the inherent risk and cost. Formal approaches that allow for investigating distributed firewall configuration space systematically are highly needed to optimize decision support under multiple design constraints. The objective of this paper is to automatically synthesize the implementation of distributed filtering architecture and configuration that will minimize security risk while considering connectivity requirements, user usability and budget constraints. Our automatic synthesis generates not only the complete rule configuration for each firewall to satisfy risk and connectivity constraints, but also the optimal firewall placement in the networks to minimizes spurious traffic. We define fine-grain risk, usability and cost metrics tunable to match business requirements, and formalize the configuration synthesis as an optimization problem. We then show that distributed firewall synthesis is an NP-hard problem and provide heuristic approximation algorithms. We implemented our approach in a tool called FireBlanket that were rigorously evaluated under different network sizes, topologies and budget requirements. Our evaluation study shows that the results obtained by FireBlanket are close to the theoretical lower bound and the performance is scalable with the network size.
机译:防火墙是计算机网络中部署最多的安全设备。尽管如此,设计和配置分布式防火墙(包括确定访问控制规则和设备在网络中的位置)仍然是一项非常复杂的任务,因为它需要在连接性要求与固有风险和成本之间取得平衡。迫切需要采用正式方法来系统研究分布式防火墙配置空间,以优化在多个设计约束下的决策支持。本文的目的是自动综合分布式过滤体系结构和配置的实现,以在考虑连接性要求,用户可用性和预算约束的同时最大程度地降低安全风险。我们的自动综合功能不仅可以为每个防火墙生成完整的规则配置,以满足风险和连接性约束,还可以在网络中优化防火墙的位置,以最大程度地减少虚假流量。我们定义了可微调的细粒度风险,可用性和成本指标,以匹配业务需求,并将配置综合形式化为优化问题。然后,我们证明分布式防火墙综合是一个NP难题,并提供了启发式近似算法。我们在名为FireBlanket的工具中实施了我们的方法,该工具在不同的网络规模,拓扑和预算要求下进行了严格评估。我们的评估研究表明,FireBlanket获得的结果接近理论下限,并且性能可随网络规模扩展。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号