首页> 外文会议>IEEE Symposium on Computer and Communications >Tuple Based Approach for Anomalies Detection within Firewall Filtering Rules
【24h】

Tuple Based Approach for Anomalies Detection within Firewall Filtering Rules

机译:基于元组方法在防火墙过滤规则中的异常检测方法

获取原文

摘要

Firewalls implement packet filtering and thereby provide security functions that are used to manage data flow to, from and through routers based on a set of predefined filtering rules. Hence, filtering rules have to be well defined and coherent in order to guarantee the desired responses of the firewall. In this paper, we propose a new approach for detecting anomalies in the firewall filtering rules. An anomaly occurs when the domains of two given filtering rules are not disjoint. Filtering rules relationships have a structure of an algebraic semi group (R,∧), and via a morphism, we transform the problem from the formal writing and resolution to an analytic treatment. Our approach is more general than related works, since it treats any protocol header, any number of fields and different IP address writing, and, as a result, we define new anomalies such as Contradiction Anomaly and other types of the Redundancy Anomaly. We have implemented our technique and the first experimental tests show its efficiency and simplicity.
机译:防火墙实现数据包过滤,从而提供用于根据一组预定义的过滤规则管理到从和通过路由器管理数据流的安全功能。因此,过滤规则必须定义和连贯,以保证防火墙的所需响应。在本文中,我们提出了一种用于检测防火墙过滤规则中的异常的新方法。当两个给定的过滤规则的域不脱节时发生异常。过滤规则关系具有代数半组(R,∧)和通过态度的结构,我们将问题从正式写作和分辨率转变为分析治疗。我们的方法比相关的作品更广泛,因为它处理任何协议标题,任何数量的字段和不同的IP地址写作,以及我们定义了新的异常,如矛盾异常和其他类型的冗余异常。我们已经实施了我们的技术,第一个实验测试表明其效率和简单。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号