首页> 外文期刊>Concurrency and computation: practice and experience >A new approach to designing firewall based on multidimensional matrix
【24h】

A new approach to designing firewall based on multidimensional matrix

机译:基于多维矩阵的防火墙设计新方法

获取原文
获取原文并翻译 | 示例

摘要

Firewalls are crucial elements to enhance network security by examining the field value of every packet andrndecide whether to accept or discard the packet according to the firewall policy. However, the design ofrnfirewall policies, especially for enterprise networks, is complex and error-prone. This paper aims to proposernan effective firewall design method to ensure the consistency, compactness and completeness of firewallrnrules. Specifically, we develop a new designing model, namely firewall design matrix, and the correspondingrnconstruction algorithm for mapping firewall rules to firewall design matrix. A firewall generation algorithm isrnproposed to generate the target firewall rules that are equivalent to the original ones while maintaining therncompleteness. Theoretical proof and extensive experiments on both real-world and synthetic firewalls arernconducted to evaluate the performance of the proposed method. The results demonstrate that it can achieverna high compression ratio efficiently while maintaining the firewall rules conflict-free.
机译:防火墙是通过检查每个数据包的字段值并根据防火墙策略确定是接受还是丢弃数据包来增强网络安全性的关键元素。但是,防火墙策略(特别是针对企业网络)的设计复杂且容易出错。本文旨在提出一种有效的防火墙设计方法,以确保防火墙规则的一致性,紧凑性和完整性。具体来说,我们开发了一种新的设计模型,即防火墙设计矩阵,以及将防火墙规则映射到防火墙设计矩阵的相应构造算法。提出了一种防火墙生成算法,以在保持完整性的同时生成与原始防火墙等效的目标防火墙规则。进行了理论上的证明和在实际和综合防火墙上的广泛实验,以评估所提出方法的性能。结果表明,在保持防火墙规则无冲突的同时,它可以有效地实现较高的压缩率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号