首页> 外文期刊>International Journal of Computer Trends and Technology >Designing Of Distributed Firewalls in Co-operative Domains
【24h】

Designing Of Distributed Firewalls in Co-operative Domains

机译:合作域中的分布式防火墙设计

获取原文
       

摘要

Firewalls have been broadly organized on the Internet aimed at acquiring secluded systems. A ?rewall forms every received or departing packet towards to choose whether to receive or reject the packet grounded on its strategy. Improving ?rewall strategies is vital aimed at enlightening system performance. Earlier effort on ?rewall optimization emphases on both intra ?rewall or inter ?rewall optimization inside single organizational field anywhere the confidentiality of ?rewall strategies is not an apprehension. This paper discovers inter ?rewall optimization transversely organizational fields aimed at the initial time. The key procedural contest remains that ?rewall strategies cannot be shared across domains because a ?rewall policy contains con?dential information and even potential security holes, which can be exploited by attackers. In this paper, we recommend the ?rst fractious field confidentiality preservative obliging ?rewall strategy optimization procedure. Probably, aimed at some binary composed ?rewalls be appropriate towards to binary dissimilar organizational fields, our procedure can recognize in every ?rewall the instructions that are able to remove since of the additional ?rewall. The optimization process comprises obliging calculation among the dual ?rewalls without any gathering revealing its rule to the additional. We executed our procedure and directed farreaching experimentations. The consequences happening actual ?rewall strategies demonstration that our protocol can eliminate as many as 49% of the instructions in a ?rewall, while the regular is 19.4%. The statement charge is less than an insufficient 100 kilobytes. Our procedure in added connected package dispensation above, and the of?ine dispensation period is less than an insufficient 100 seconds.
机译:防火墙在Internet上进行了广泛的组织,旨在获取隐蔽的系统。防火墙形成每个接收或离开的数据包,以选择接收还是拒绝基于其策略的数据包。改进防火墙策略对于提高系统性能至关重要。在不担心防火墙策略机密性的任何地方,针对防火墙优化的早期工作都将重点放在单个组织内部的防火墙内部或防火墙间优化上。本文发现了针对初始时间的墙间优化横向组织领域。关键的程序竞争仍然是,防火墙策略不能包含跨域共享,因为防火墙策略包含机密信息甚至潜在的安全漏洞,攻击者可以利用这些漏洞。在本文中,我们建议使用第一个分形场机密性保护策略来优化策略。可能是针对一些二进制组成的防火墙,这些二进制防火墙适合于二进制不同的组织领域,我们的过程可以在每个防火墙中识别由于附加防火墙而能够删除的指令。优化过程包括强制在两个防火墙之间进行计算,而不会进行任何收集以将其规则透露给其他防火墙。我们执行了程序并进行了影响深远的实验。实际的防火墙策略所产生的后果表明,我们的协议可以消除防火墙中多达49%的指令,而常规规则为19.4%。对帐单费用不足100 KB。我们在以上添加的连接式包装分配过程中,最终分配时间少于100秒。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号