...
首页> 外文期刊>Future generation computer systems >Improving cloud network security using the Tree-Rule firewall
【24h】

Improving cloud network security using the Tree-Rule firewall

机译:使用Tree-Rule防火墙提高云网络安全性

获取原文
获取原文并翻译 | 示例
           

摘要

This study proposes a new model of firewall called the Tree-Rule Firewall', which offers various benefits and is applicable for large networks such as 'cloud' networks. The recently available firewalls (i.e., Listed-Rule firewalls) have their limitations in performing the tasks and are inapplicable for working on some networks with huge firewall rule sizes. The Listed-Rule firewall is mathematically tested in this paper to prove that the firewall potentially causes conflict rules and redundant rules and hence leads to problematic network security systems and slow functional speed. To overcome these problems, we show the design and development of Tree-Rule firewall that does not create conflict rules and redundant rules. In a Tree-Rule firewall, the rule positioning is based on a tree structure instead of traditional rule listing. To manage firewall rules, we implement a Tree-Rule firewall on the Linux platform and test it on a regular network and under a cloud environment respectively to show its performance. It is demonstrated that the Tree-Rule firewall offers better network security and functional speed than the Listed-Rule firewall. Compared to the Listed-Rule firewall, rules of the Tree-Rule firewall are easier to be created, especially on a large network such as a cloud network.
机译:这项研究提出了一种名为“树规则防火墙”的新型防火墙,该防火墙具有多种优点,适用于诸如“云”网络之类的大型网络。最近可用的防火墙(即列出规则的防火墙)在执行任务时有其局限性,不适用于在具有巨大防火墙规则大小的某些网络上工作。本文对Listed-Rule防火墙进行了数学测试,以证明该防火墙可能导致冲突规则和冗余规则,从而导致出现问题的网络安全系统和较慢的功能速度。为了克服这些问题,我们展示了不创建冲突规则和冗余规则的Tree-Rule防火墙的设计和开发。在树规则防火墙中,规则定位基于树结构,而不是传统的规则列表。为了管理防火墙规则,我们在Linux平台上实现了Tree-Rule防火墙,并分别在常规网络和云环境下对其进行了测试,以显示其性能。事实证明,树形规则防火墙比列表规则防火墙提供了更好的网络安全性和功能速度。与List-Rule防火墙相比,Tree-Rule防火墙的规则更易于创建,尤其是在大型网络(如云网络)上。

著录项

  • 来源
    《Future generation computer systems》 |2014年第1期|116-126|共11页
  • 作者单位

    School of Computing and Communications, Faculty of Engineering and Information Technology, University of Technology, Sydney, Australia;

    School of Computing and Communications, Faculty of Engineering and Information Technology, University of Technology, Sydney, Australia;

    School of Computing and Communications, Faculty of Engineering and Information Technology, University of Technology, Sydney, Australia;

    School of Computing and Communications, Faculty of Engineering and Information Technology, University of Technology, Sydney, Australia;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Firewall; Tree-Rule firewall; Network security; Cloud security; Cloud computing;

    机译:防火墙;树规则防火墙;网络安全;云安全;云计算;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号