首页> 外文期刊>International Journal of Engineering and Technology >MEASURING THE EFFECTIVENESS AND EFFICIENCY OF RULE REORDERING ALGORITHM FOR POLICY CONFLICT
【24h】

MEASURING THE EFFECTIVENESS AND EFFICIENCY OF RULE REORDERING ALGORITHM FOR POLICY CONFLICT

机译:评估政策冲突算法的规则重排算法的有效性和效率

获取原文
       

摘要

Network security has acquired appreciable attention among business communities. Firewall act as a frontier defense and plays a significant role for establishing secure communication in networks against unauthorized traffic occurred in network. Firewall policies deployed in firewall, directs the firewalls to handle network traffic for particular IP addresses and protocols. Although deployment of firewall technology improves security in our network, managing firewall policies is a challengeable process due to the composite character of rules in firewall policy, on the other hand policy rules created by the system administrators face difficulty in resolving policy conflicts. To address all the aforementioned issues, we need effective firewall conflict management framework. In this effort, we propose efficacious framework to treat the policy conflict in firewalls based on risk assessment of conflicts. We identify the risk level of the policy conflict on the basis of vulnerability assessment in the secured network. Our major contribution in this paper involves the utilization of novel technique called Dynamic Rule Reordering that effectively optimizes the filtering policies in firewall. The proposed Rule reordering algorithm dynamically optimizes the conflicted rule reordering and leads to the accomplishment of most ideal solution for conflict resolution. We perform extensive evaluation and experiments to show the efficiency of our proposed rule reordering, which reorder the conflicted rules.
机译:网络安全已在企业界引起了极大的关注。防火墙充当边界防御,并在建立网络中的安全通信以防止网络中发生未经授权的流量方面发挥重要作用。部署在防火墙中的防火墙策略指导防火墙处理特定IP地址和协议的网络流量。尽管部署防火墙技术可以提高我们网络的安全性,但是由于防火墙策略中规则的综合特征,因此管理防火墙策略是一个具有挑战性的过程,另一方面,系统管理员创建的策略规则在解决策略冲突方面面临困难。为了解决所有上述问题,我们需要有效的防火墙冲突管理框架。在这项工作中,我们提出了基于冲突风险评估的有效框架来处理防火墙中的策略冲突。我们基于安全网络中的漏洞评估来确定策略冲突的风险级别。我们在本文中的主要贡献涉及利用称为动态规则重排序的新技术,该技术可有效优化防火墙中的过滤策略。所提出的规则重排序算法动态地优化了冲突规则重排序,并导致解决冲突的最理想解决方案的实现。我们进行了广泛的评估和实验,以证明我们提出的规则重新排序的效率,该规则可以对冲突的规则进行重新排序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号