【24h】

Detecting and resolving packet filter conflicts

机译:检测并解决数据包过滤器冲突

获取原文
获取外文期刊封面目录资料

摘要

Packet filters are rules for classifying packets based on their header fields. Packet classification is essential to routers supporting services such as quality of service (QoS), virtual private networks (VPNs), and firewalls. A filter conflict occurs when two or more filters overlap, creating an ambiguity in packet classification. Current techniques for resolving filter conflicts are based on prioritizing conflicting filters, and choosing the higher priority filter. We show that such ordering does not always work. Instead, we propose a new scheme for conflict resolution, which is based on the idea of adding resolve filters. Our main results are algorithms for detecting and resolving conflicts in a filter database. We have tried our algorithm on 3 existing firewall databases, and have found conflicts, which are potential security holes, in each of them.
机译:数据包过滤器是用于根据数据包的标头字段对数据包进行分类的规则。数据包分类对于支持诸如服务质量(QoS),虚拟专用网络(VPN)和防火墙之类的服务的路由器至关重要。当两个或多个过滤器重叠时会发生过滤器冲突,从而在数据包分类中造成歧义。解决过滤器冲突的当前技术基于对冲突过滤器进行优先级排序,并选择优先级更高的过滤器。我们证明这种排序并不总是有效。相反,我们基于添加解析过滤器的想法,提出了一种新的冲突解决方案。我们的主要结果是用于检测和解决过滤器数据库中冲突的算法。我们已经在3个现有的防火墙数据库上尝试了我们的算法,并在每个数据库中发现了冲突,这些冲突是潜在的安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号