首页> 外文期刊>Advances in Science, Technology and Engineering Systems >Decision Making System for Improving Firewall Rule Anomaly Based on Evidence and Behavior
【24h】

Decision Making System for Improving Firewall Rule Anomaly Based on Evidence and Behavior

机译:基于证据和行为改善防火墙规则异常的决策制度

获取原文
       

摘要

Firewalls are controlled by rules which often incur anomalies. The anomalies are considered serious problems that administrators do not desire to happen over their firewalls because they cause more vulnerabilities and decrease the overall performance of the firewall. Resolving anomaly rules that have already occurred on the firewall is difficult and mainly depends on the firewall administrator’s discretion. In this paper, a model is designed and developed to assist administrators to make effective decisions for optimizing anomaly rules using the probability approach (Bayesian). In this model, the firewall needs to add four property fields (Extra fields) to the firewall rules: frequency of packets matching against rules, evidence of creating rules, the expertise of rules creator and protocol priority. These fields are used to calculate the probability of each firewall rule. The probability for each rule is used while the rules conflict and administrators need to resolve them. The rule having the highest probability value indicates that it has the highest priority in consideration. Experimental results show that the proposed model allows firewall administrators to make significant decisions about solving anomaly rules. The data structure of this model is based on k-ary tree, therefore the speed of building tree, time complexity and space complexity: O(n), O(logmn) and O(m*n) respectively. Besides, the confidence of the proposed firewall for resolving firewall rule anomalies of the administrator increase by 29.6% against the traditional firewall, and the reliability value between the inter-raters also increase by 13.1%.
机译:防火墙由规则控制,通常会产生异常。异常被认为是管理员不希望发生在防火墙上的严重问题,因为它们会导致更脆弱性并降低防火墙的整体性能。解决已经发生在防火墙上的异常规则是困难的,主要取决于防火墙管理员的自由裁量权。在本文中,设计和开发了一种模型,以帮助管理员利用概率方法(贝叶斯)进行优化异常规则的有效决策。在此模型中,防火墙需要向防火墙规则添加四个属性字段(额外字段):与规则匹配的数据包频率,创建规则的证据,规则创建者和协议优先级的专业知识。这些字段用于计算每个防火墙规则的概率。使用规则冲突和管理员需要解决这些规则的概率。具有最高概率值的规则表示它具有最高优先级考虑。实验结果表明,该拟议的模型允许防火墙管理员对解决异常规则做出重大决策。该模型的数据结构基于K-ary树,因此构建树,时间复杂度和空间复杂度:O(n),O(logmn)和o(m * n)的速度。此外,建议防火墙的信心解决管理人员的防火墙规则异常,对传统防火墙的增加29.6%,互联网间的可靠性值也增加了13.1%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号