首页> 中文期刊> 《计算机工程》 >基于默认规则的防火墙优化方法

基于默认规则的防火墙优化方法

         

摘要

提出一种基于默认规则的防火墙优化方法,根据规则的匹配概率及防火墙日志,从默认规则中分离出简单规则,分析这些规则与原规则的关系,并合并成新的规则.评价规则对防火墙性能的影响,并选择性地加入防火墙规则库,实现防火墙线性匹配优化.实验结果表明,该方法在一般情况下能有效降低规则的平均匹配次数,提高防火墙性能.%This paper proposes a firewall-optimization method based on default-rules. This method begins by the matching probability of firewall rules, extracting some simple rules from the default-rules based on the firewall logs. After analyzing the relationship between the simple rules and the existing rules, these simple rules are emerged into the new rules. The impacts of these new rules are evaluated on the firewall and some new rules are added to the rules library selectively, to implement the optimization for the linear match of the firewall. Experimental results show that, this method can reduce the average number of rules matches, elevating the performance of firewall.

著录项

相似文献

  • 中文文献
  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号