首页> 外文会议>ACM workshop on Formal methods in security engineering >Automatic analysis of firewall and network intrusion detection system configurations
【24h】

Automatic analysis of firewall and network intrusion detection system configurations

机译:自动分析防火墙和网络入侵检测系统的配置

获取原文

摘要

Given a network that deploys multiple firewalls and network intrusion detection systems (NIDSs), ensuring that these security components are correctly configured is a challenging problem. Although models have been developed to reason independently about the effectiveness of firewalls and NIDSs, there is no common framework to analyze their interaction. This paper presents an integrated, constraint-based approach for modeling and reasoning about these configurations. Our approach considers the dependencies among the two types of components, and can reason automatically about their combined behavior. We have developed a tool for the specification and verification of networks that include multiple firewalls and NIDSs, based on this approach. This tool can also be used to automatically generate NIDS configurations that are optimal relative to a given cost function.>>> af++ WO2011115856A3 . 2012-02-02

机译:提供应用层防火墙和集成深度数据包检查功能的方法,系统和计算机可读介质,以在边缘网络设备上提供早期入侵检测和入侵预防

  • 机译:用于提供应用层防火墙和集成深度包检查功能的方法,系统和计算机可读介质,用于在边缘网络设备上提供早期入侵检测和入侵防御

  • 机译:提供应用层防火墙和集成深度数据包检查功能的方法,系统和计算机可读介质,以在边缘网络设备上提供早期入侵检测和入侵预防

  • 获取原文

    客服邮箱:kefu@zhangqiaokeyan.com

    京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
    • 客服微信

    • 服务号