首页> 外文会议>International Joint Conference on E-Business and Telecommunications >A HEURISTIC POLYNOMIAL ALGORITHM FOR LOCAL INCONSISTENCY DIAGNOSIS IN FIREWALL RULE SETS
【24h】

A HEURISTIC POLYNOMIAL ALGORITHM FOR LOCAL INCONSISTENCY DIAGNOSIS IN FIREWALL RULE SETS

机译:防火墙规则集中局部不一致诊断的启发式多项式算法

获取原文

摘要

Firewall ACLs can contain inconsistencies. There is an inconsistency if different actions can be taken on the same flow of traffic, depending on the ordering of the rules. Inconsistent rules should be notified to the system administrator in order to remove them. Minimal diagnosis and characterization of inconsistencies is a combinatorial problem. Although many algorithms have been proposed to solve this problem, all reviewed ones work with the full ACL with no approximate heuristics, giving minimal and complete results, but making the problem intractable for large, real-life ACLs. In this paper we take a different approach. First, we deeply analyze the inconsistency diagnosis in firewall ACLs problem, and propose to split the process in several parts that can be solved sequentially: inconsistency detection, inconsistent rules identification, and inconsistency characterization. We present polynomial heuristic algorithms for the first two parts of the problem: detection and identification (diagnosis) of inconsistent rules. The algorithms return several independent clusters of inconsistent rules that can be characterized against a fault taxonomy. These clusters contains all inconsistent rules of the ACL (algorithms are complete), but the algorithms not necessarily give the minimum number of clusters. The main advantage of the proposed heuristic diagnosis process is that optimal characterization can be now applied to several smaller problems (the result of the diagnosis process) rather than to the whole ACL, resulting in an effective computational complexity reduction at the cost of not having the minimal diagnosis. Experimental results with real ACLs are given.
机译:防火墙ACL可以包含不一致的。如果可以在相同的流量流程上采取不同的操作,则存在不一致,具体取决于规则的排序。应通知系统管理员以删除不一致规则以删除它们。最小的诊断和表征不一致是一个组合问题。虽然已经提出了许多算法来解决这个问题,但所有审查的那些都与全ACL一起工作,没有近似启发式,效果最小,结果,但是对于大型现实的ACL的问题难以解决。在本文中,我们采取了不同的方法。首先,我们深入分析防火墙ACL问题中的不一致诊断,并建议将过程拆分为可以顺序解决的几个部分:不一致检测,不一致的规则识别和不一致性格。我们为问题的前两个部分提供多项式启发式算法:检测和识别(诊断)不一致规则。该算法返回几个独立的不一致规则集群,可以针对错误分类。这些群集包含ACL的所有不一致规则(算法是完整的),但算法不一定提供最小群集数。拟议的启发式诊断过程的主要优点是,现在可以应用最佳表征(诊断过程的结果)而不是整个ACL,导致不具有的成本降低了有效的计算复杂性降低最小的诊断。给出了真实ACL的实验结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号