首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Detecting and Resolving Firewall Policy Anomalies
【24h】

Detecting and Resolving Firewall Policy Anomalies

机译:检测并解决防火墙策略异常

获取原文
获取原文并翻译 | 示例

摘要

The advent of emerging computing technologies such as service-oriented architecture and cloud computing has enabled us to perform business services more efficiently and effectively. However, we still suffer from unintended security leakages by unauthorized actions in business services. Firewalls are the most widely deployed security mechanism to ensure the security of private networks in most businesses and institutions. The effectiveness of security protection provided by a firewall mainly depends on the quality of policy configured in the firewall. Unfortunately, designing and managing firewall policies are often error prone due to the complex nature of firewall configurations as well as the lack of systematic analysis mechanisms and tools. In this paper, we represent an innovative policy anomaly management framework for firewalls, adopting a rule-based segmentation technique to identify policy anomalies and derive effective anomaly resolutions. In particular, we articulate a grid-based representation technique, providing an intuitive cognitive sense about policy anomaly. We also discuss a proof-of-concept implementation of a visualization-based firewall policy analysis tool called Firewall Anomaly Management Environment (FAME). In addition, we demonstrate how efficiently our approach can discover and resolve anomalies in firewall policies through rigorous experiments.
机译:诸如面向服务的体系结构和云计算之类的新兴计算技术的出现使我们能够更有效地执行业务服务。但是,我们仍然会遭受未经授权的商业服务操作而导致的安全意外泄漏。防火墙是部署最广泛的安全机制,可确保大多数企业和机构中专用网络的安全。防火墙提供的安全保护的有效性主要取决于防火墙中配置的策略的质量。不幸的是,由于防火墙配置的复杂性以及缺乏系统的分析机制和工具,设计和管理防火墙策略通常容易出错。在本文中,我们代表了一种创新的防火墙策略异常管理框架,它采用基于规则的分段技术来识别策略异常并得出有效的异常解决方案。特别是,我们阐明了基于网格的表示技术,从而提供了有关策略异常的直观认知。我们还将讨论名为防火墙异常管理环境(FAME)的基于可视化的防火墙策略分析工具的概念验证实现。此外,我们通过严格的实验演示了我们的方法如何有效地发现和解决防火墙策略中的异常情况。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号