首页> 外文会议>International Conference on Information Technology >Automatic Verification of Security Policies in Firewalls with Dynamic Rule Sequence
【24h】

Automatic Verification of Security Policies in Firewalls with Dynamic Rule Sequence

机译:用动态规则序列自动验证防火墙中的安全策略

获取原文

摘要

Security policies play an important role in the security of communication networks. They are normally defined at a high level of abstraction and implemented in firewalls, which are the first defense to secure networks against attacks and unauthorized access. When security policies are implemented in firewalls, anomalities and conflicts that may arise from different policies should be taken into consideration. On the other hand, Firewalls conduct random sequence order shuffling during their operation to prevent certain security attacks. This may result in an incorrect implementation of high level policies that depend on the order of rules inspection in the firewall. This paper presents a formal model of firewall rules sequence and a novel method that verifies the set of security policies when rules sequence changes. The method is tested on synthetic firewall of practical size, where the obtained results demonstrate the ability of firewalls to maintain the functional behavior of security policies during their runtime operation. The detailed analysis shows that the proposed method can be applied on firewalls with dynamic rule sequence in real time.
机译:安全政策在通信网络的安全方面发挥着重要作用。它们通常以高级别的抽象定义,并在防火墙中实现,这是第一次防御攻击和未经授权的访问的防御。当安全策略在防火墙中实现时,应考虑来自不同政策可能出现的异常和冲突。另一方面,防火墙在操作过程中进行随机序列顺序洗机,以防止某些安全攻击。这可能导致依赖防火墙中规则检测顺序的高级策略的实施不正确。本文介绍了防火墙规则序列的正式模型和一种新的方法,当规则序列更改时验证安全策略集。该方法在实际规模的合成防火墙上进行了测试,其中所获得的结果表明防火墙在运行时操作期间维持安全策略功能行为的能力。详细分析表明,所提出的方法可以实时使用动态规则序列对防火墙应用于防火墙上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号