首页> 外文会议>International Multitopic Conference >Analyzing and Resolving Anomalies in Firewall Security Policies Based on Propositional Logic
【24h】

Analyzing and Resolving Anomalies in Firewall Security Policies Based on Propositional Logic

机译:基于命题逻辑的防火墙安全策略中分析与解决异常

获取原文

摘要

Firewalls are essential components in network security solutions. In order to implement correct security policy, the anomalies in firewall rules should be analyzed carefully, especially in enterprise network. In this paper, we present a new formal framework for analysis and resolution of anomalies in firewall rules. First of all, a formal model based on propositional logic is presented to specify rules. Then we specify all anomalies that identified in the latest researches based on our model. Current studies for analysis of anomalies are based on one to one rule anomalies, but we identify total version of anomalies based on one to many relationship of rules. Furthermore we have designed and implemented a tool based on theorem proving for verification of the specified anomalies. In addition, we present two algorithms for resolving anomalies in a rule database based on our formal model. These algorithms minimize the number of rales without changing the policy. Experimental results indicate that our algorithms for discovery single and total anomalies run in 2-3 seconds for a very large firewall with thousands of rules.
机译:防火墙是网络安全解决方案中的重要组成部分。为了实现正确的安全策略,应仔细分析防火墙规则中的异常,尤其是在企业网络中。在本文中,我们为防火墙规则中的异常分析和解决了一个新的正式框架。首先,提出了一个基于命题逻辑的正式模型来指定规则。然后我们指定基于我们模型的最新研究中确定的所有异常。目前的异常分析研究基于一对一的规则异常,但我们根据一对一的规则关系确定异常的总版本。此外,我们根据证明的定理设计和实现了用于验证指定异常的工具。此外,我们介绍了两个用于根据我们的正式模型在规则数据库中解析异常的算法。这些算法最小化了rales的数量而不改变策略。实验结果表明,我们的发现单一和总异常的算法在2-3秒内运行,对于具有数千条规则的非常大的防火墙。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号