【24h】

AFPL, an Abstract Language Model for Firewall ACLs

机译:AFPL,防火墙ACL的抽象语言模型

获取原文

摘要

Design and management of firewall rule sets is difficult and error prone, mainly because the translation of access control requirements to low level languages is difficult. Abstract languages have been proposed, but none have been adopted by the industry. We think that the main reason is that their complexity is close to many of the existing low level languages. Complexity is defined as the difficulty to express knowledge from the reality being modeled (access control requirements). In this paper, we analyze the most widely used firewall languages and different possibilities of abstraction. Based on this analysis, a model for Firewall languages is proposed, and a new simple yet expressive and powerful firewall abstract language, Abstract Firewall Policy Language (AFPL), is proposed. AFPL can then be translated to existing low level firewall languages, or be directly interpreted by firewall platforms. We expect that AFPL can fill the gap between requirements and low level firewall languages.
机译:防火墙规则集的设计和管理是困难的,容易出错,主要是因为对低级语言的访问控制要求的翻译很难。已经提出了抽象语言,但行业也没有采用。我们认为主要原因是他们的复杂性接近许多现有的低级语言。复杂性被定义为表达来自所建模的现实的知识(访问控制要求)。在本文中,我们分析了最广泛使用的防火墙语言和不同的抽象可能性。基于该分析,提出了一种防火墙语言模型,提出了一种新的简单又表达和强大的防火墙摘要语言,抽象防火墙策略语言(AFPL)。然后可以将AFPL转换为现有的低级防火墙语言,或直接由防火墙平台解释。我们预计AFPL可以填补需求和低级防火墙语言之间的差距。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号