首页> 外文期刊>International journal of computer science and network security >A Mapping Mechanism for Periodic Filters in a Conflict Detection System for Time-Based Firewall Policies
【24h】

A Mapping Mechanism for Periodic Filters in a Conflict Detection System for Time-Based Firewall Policies

机译:基于时间的防火墙策略在冲突检测系统中定期过滤器的映射机制

获取原文
获取原文并翻译 | 示例

摘要

Recently, time-based filters are introduced in several practical firewalls like CISCO ACLs and LINUX Iptables to control network traffic in time. It is very handy when a service is required to be available at certain times of a day or at certain days. However, network administrators struggle to maintain time-based firewall policies due to their high-complexity. Conflict is a misconfiguration that occurs when a packet matches two or more filters. It makes the filters either redundant or shadowed, and as a result the network does not reflect the actual configurations of the time-based firewall policies. Even though, conflict detection techniques for time-based filters have been proposed, it takes huge computation time and memory when the conflict detection period is too long due to the enormous repetition of periodic time-based filters. To solve this problem, we have proposed a mapping mechanism to treat the periodic filters and remove the unnecessary repetitions of the periodic filters which reduces the huge computation time and memory. Furthermore, we have evaluated the feasibility and the usefulness of the proposed system by carrying out experiments with the available conflict detection systems with various time-based firewall policies, and have proved the effectiveness of the mapping mechanism.
机译:最近,在一些实用的防火墙(如CISCO ACL和LINUX Iptables)中引入了基于时间的过滤器,以及时控制网络流量。当需要在一天中的某些时间或某些天提供服务时,这非常方便。但是,由于网络管理员的高度复杂性,他们难以维护基于时间的防火墙策略。冲突是一种错误配置,当数据包与两个或多个过滤器匹配时发生。它使过滤器变得多余或被遮蔽,结果网络无法反映基于时间的防火墙策略的实际配置。即使已经提出了基于时间的过滤器的冲突检测技术,但是由于周期性基于时间的过滤器的大量重复而导致冲突检测时间过长时,它将花费大量的计算时间和内存。为了解决这个问题,我们提出了一种映射机制来处理周期滤波器,并消除了周期滤波器不必要的重复,从而减少了计算时间和内存。此外,我们通过对具有各种基于时间的防火墙策略的可用冲突检测系统进行实验,评估了该系统的可行性和实用性,并证明了该映射机制的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号