首页> 外文期刊>Journal of High Speed Networks >On autonomic optimization of firewall policy organization
【24h】

On autonomic optimization of firewall policy organization

机译:论防火墙策略组织的自主优化

获取原文
获取原文并翻译 | 示例
           

摘要

Security policies play a critical role in many of the current network security technologies such as firewalls, IPSec and IDS devices. The configuration of these policies not only determines the functionality of such devices, but also substantially affects their performance. The optimization of filtering policy configuration is critically important to provide high performance packet filtering particularly for high speed network security. Current packet filtering techniques exploit the characteristics of the filtering policies, but they do not consider the traffic behavior in optimizing their search data structures. This often results in Unpractically high space complexity, which undermines the performance gain offered by these techniques. Also, these techniques offer upper bounds for the worst case search times; nevertheless, the more common average case scenarios are not necessarily optimized. Moreover, the types of packet filtering fields used in most of these techniques are limited to IP header fields and cannot be generalized to cover transport and application layer filtering. In this paper, we present a novel technique that utilizes Internet traffic characteristics to optimize the organization of firewall policies. The proposed technique timely adapts to the traffic conditions using actively calculated statistics to dynamically optimize the ordering of packet filtering rules. The rule importance in traffic matching as well as its dependency on other rules are both considered in our optimization algorithm. Through extensive evaluation experiments using simulated and real Internet traffic traces, the proposed mechanism is shown to be efficient and easy to deploy in practical firewall implementations.
机译:安全策略在许多当前的网络安全技术(例如防火墙,IPSec和IDS设备)中扮演着至关重要的角色。这些策略的配置不仅决定了此类设备的功能,而且还大大影响了它们的性能。过滤策略配置的优化对于提供高性能的数据包过滤(特别是对于高速网络安全性)至关重要。当前的数据包过滤技术利用了过滤策略的特征,但是在优化其搜索数据结构时并未考虑流量行为。这通常导致不切实际的高空间复杂性,从而破坏了这些技术所提供的性能。同样,这些技术为最坏情况的搜索时间提供了上限。但是,更常见的平均情况场景并不一定要优化。而且,在大多数这些技术中使用的分组过滤字段的类型仅限于IP头字段,并且不能一概而论以涵盖传输和应用程序层过滤。在本文中,我们提出了一种利用Internet流量特性来优化防火墙策略组织的新颖技术。所提出的技术使用主动计算的统计信息来动态地优化分组过滤规则的排序,从而适时地适应交通状况。我们在优化算法中同时考虑了流量匹配中规则的重要性及其对其他规则的依赖性。通过使用模拟和真实Internet流量跟踪进行的广泛评估实验,表明该机制在实际的防火墙实现中是高效且易于部署的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号