首页> 外文期刊>Computing and informatics >MANAGEMENT AND VERIFICATION OF FIREWALL AND ROUTER ACCESS LISTS
【24h】

MANAGEMENT AND VERIFICATION OF FIREWALL AND ROUTER ACCESS LISTS

机译:防火墙和路由访问列表的管理和验证

获取原文
获取原文并翻译 | 示例

摘要

Security in computer networks is a very complex task especially if it is required to separate a corporate network from public Internet or to divide a company's intranet into multiple zones with different security requirements. The network security policy that describes these security requirements is primarily presented in a high-level form. Also, the security policy is enforced using some low-level security mechanisms, mainly firewall technology. One of the main difficulties faced by the network administrator is how to translate the high-level policy description to the low-level firewall rule-base. This paper presents Role-Based Network Security (RBNS) model that can be used as an intermediary level between high-level policy form and low-level firewall rule-base. We use the Role-Based Access Control (RBAC) model as a framework for our proposed RBNS model. The main concept of RBNS model is that network services are assigned to roles and hosts are made members of appropriate roles thereby acquiring the roles' network services. Also, the paper presents a compilation algorithm that can be used to automatically generate the low-level firewall rule-base from the RBNS intermediary-level. The paper presents a proposed verification algorithm to prove that the high-level policy and the translated low-level firewall rule-base are equivalent. Based on the RBNS model, we design and implement a firewall management toolkit. The paper demonstrates in brief the toolkit's capabilities through an example, thus showing that the using of this model separates the high-level security policy from the underlying enforcement mechanism. This separation offers easier management and debugging of low-level firewall rule-base at an an appropriate level of abstraction.
机译:计算机网络中的安全性是一项非常复杂的任务,尤其是在需要将公司网络与公共Internet分开或将公司的Intranet划分为具有不同安全性要求的多个区域的情况下。描述这些安全要求的网络安全策略主要以高级形式提供。同样,使用一些低级安全机制(主要是防火墙技术)来实施安全策略。网络管理员面临的主要困难之一是如何将高级策略描述转换为低级防火墙规则库。本文提出了基于角色的网络安全(RBNS)模型,该模型可以用作高级策略形式和低级防火墙规则库之间的中间层。我们使用基于角色的访问控制(RBAC)模型作为我们提出的RBNS模型的框架。 RBNS模型的主要概念是将网络服务分配给角色,并使主机成为相应角色的成员,从而获取角色的网络服务。另外,本文提出了一种编译算法,该算法可用于从RBNS中间层自动生成低级防火墙规则库。本文提出了一种验证算法,以证明高级策略和转换后的低级防火墙规则库是等效的。基于RBNS模型,我们设计并实现了防火墙管理工具包。本文通过一个示例简要演示了该工具包的功能,从而表明使用此模型可以将高级安全策略与底层的执行机制区分开。这种分离可以在适当的抽象级别上简化底层防火墙规则库的管理和调试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号