首页> 外文期刊>International journal of computer science and network security >Detecting Policy Anomalies in Firewalls by Relational Algebra and Raining 2D-Box Model
【24h】

Detecting Policy Anomalies in Firewalls by Relational Algebra and Raining 2D-Box Model

机译:通过关系代数和Raind 2D-Box模型检测防火墙中的策略异常

获取原文
获取原文并翻译 | 示例

摘要

Firewalls are crucial elements in the computer networks. Due to lack of tools for analyzing firewall policies, most firewalls on the internet have been plagued with policy anomalies. In this paper, we propose a method; which analyzes the firewall by using Relational Algebra and Raining 2D-Box Model. It can find out all the anomalies in the firewall rule-set in the format that is usually used by many firewall products such as Cisco Access Control List, IPTABLES, IPCHAINS and Check Point Firewall-1. While the existing analyzing methods consider the anomalies between any two rules in the firewall rule-set, we consider more than two rules together at the same time to find out the anomaly. Therefore we can find all the hidden anomalies in the firewall rule-set. Results from analyzing can be used with the proposed rules-combination method presented in this paper, to minimize the firewall rule without changing the policy. This method could help administrator to analyze and modify a complex firewall policy.
机译:防火墙是计算机网络中的关键元素。由于缺乏分析防火墙策略的工具,Internet上的大多数防火墙都受到策略异常的困扰。在本文中,我们提出了一种方法。通过使用关系代数和Raining 2D-Box模型分析防火墙。它可以以许多防火墙产品(例如,思科访问控制列表,IPTABLES,IPCHAINS和Check Point Firewall-1)通常使用的格式找出防火墙规则集中的所有异常。尽管现有的分析方法考虑了防火墙规则集中任意两个规则之间的异常,但我们同时考虑了两个以上的规则以找出异常。因此,我们可以在防火墙规则集中找到所有隐藏的异常。分析结果可与本文提出的规则组合方法一起使用,以在不更改策略的情况下最小化防火墙规则。此方法可以帮助管理员分析和修改复杂的防火墙策略。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号