首页> 外文学位 >Distributed Perimeter Firewall Policy Management Framework
【24h】

Distributed Perimeter Firewall Policy Management Framework

机译:分布式外围防火墙策略管理框架

获取原文
获取原文并翻译 | 示例

摘要

A perimeter firewall is the first line of defense that stops unwanted packets (based on defined firewall policies) entering the organization that deploys it. In the real world, every organization maintains a perimeter firewall between internet (which could be untrusted) and its own network (private network). In addition, organizations maintain internal firewalls to safeguard individual departments and data center servers based on various security and privacy requirements. In general, if we consider firewall setup in multinational organization's network environment, every branch has perimeter firewall and a set of internal firewalls. Every branch has its own security policies defined based on its specific security requirements, type of information, information processing systems, location-based compliance requirements, etc. As the branches of the multinational organizations span across the globe, managing the policies at every branch and ensuring the compliance and consistency of security policies are quite complex. Any misconfiguration of firewall policies even at a single branch may pose risk to the overall organization in terms of financial loss and reputation.;In this dissertation, we present our framework to automate the policy management of distributed perimeter firewalls of a multi-national organization. We introduce new categories of policies to support centralized management of distributed firewalls and to ensure consistency and compliance of organizational and location-based policies. We define procedures for the initialization of firewall policies and policy updates. Our scheme is highly automatic that needs minimum human intervention to incorporate a set of new policies or update existing policies in distributed firewalls.
机译:外围防火墙是阻止不必要的数据包(基于定义的防火墙策略)进入部署它的组织的第一道防线。在现实世界中,每个组织都在Internet(可能是不受信任的)和其自己的网络(专用网络)之间维护外围防火墙。此外,组织维护内部防火墙,以根据各种安全和隐私要求保护各个部门和数据中心服务器。通常,如果我们考虑在跨国公司的网络环境中设置防火墙,则每个分支机构都具有外围防火墙和一组内部防火墙。每个分支机构都根据其特定的安全性要求,信息类型,信息处理系统,基于位置的合规性要求等定义自己的安全性策略。随着跨国公司的分支机构遍布全球,在每个分支机构和分支机构管理策略确保安全策略的合规性和一致性非常复杂。即使在单个分支机构,任何防火墙策略的错误配置都可能给整个组织带来财务损失和声誉方面的风险。在本论文中,我们提出了使跨国组织的分布式外围防火墙的策略管理自动化的框架。我们引入了新的策略类别,以支持分布式防火墙的集中管理,并确保组织和基于位置的策略的一致性和合规性。我们定义了初始化防火墙策略和策略更新的过程。我们的方案是高度自动化的,需要最少的人为干预才能合并一组新策略或更新分布式防火墙中的现有策略。

著录项

  • 作者

    Maddumala, Mahesh Nath.;

  • 作者单位

    University of Missouri - Kansas City.;

  • 授予单位 University of Missouri - Kansas City.;
  • 学科 Computer science.
  • 学位 Ph.D.
  • 年度 2017
  • 页码 84 p.
  • 总页数 84
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号