...
首页> 外文期刊>Internet Research: Electronic Networking Applications and Policy >Managing semantic-aware policies in a distributed firewall scenario
【24h】

Managing semantic-aware policies in a distributed firewall scenario

机译:在分布式防火墙方案中管理语义感知策略

获取原文
获取原文并翻译 | 示例
           

摘要

Purpose - The purpose of the paper is to provide a two-tier framework for managing semantic-aware distributed firewall policies to be applied to the devices existing in one administrative domain. Design/methodology/approach - Special attention is paid to the CIM-based information model defined as the ontology to be used in this framework and the AI-based reasoning mechanisms and components used to perform the conflict discovery tasks over the distributed firewall policies. Findings - Mechanisms presented allow the solving some of the current issues of the network-centric security model being used in the Internet. The two-tier framework designed provides semantic-aware mechanisms to perform conflict detection and automatic enforcement of policy rules in the distributed firewall scenario. This framework is based on the use of a standard information model and a semantic-aware policy language to formally define (and then process) firewall policies. Research limitations/implications - Ongoing work is focused on identifying all kind of conflicts and anomalies that may exist in firewall systems; in parallel to this task a semi-automatic resolver of conflicting policies is currently under design. Practical implications - Network and security administrators can specify firewall policies and validate them to find syntactic and semantic errors (i.e. policy conflicts). A framework for automated validation and distribution of policies at different levels is included. This ensures that firewall policies produce the desired effects, facilitating the creation and maintenance of firewall rules in one administrative domain. Originality/value - A practical and novel two-tier system that provides detection of conflicts in rules existing in a distributed firewall scenario and the automatic and secure deployment of these rules. A packet-filtering model, which is simple and powerful enough for the conflict discovery and rule analysis processes, has been proposed. Moreover, ontology and rule reasoning are being proposed as techniques for the conflict detection problem in this particular scenario.
机译:目的-本文的目的是提供一个两层框架,用于管理要应用于一个管理域中存在的设备的语义感知分布式防火墙策略。设计/方法/方法-特别注意基于CIM的信息模型,该信息模型定义为在此框架中使用的本体,以及基于AI的推理机制和组件,用于在分布式防火墙策略上执行冲突发现任务。结果-提出的机制可以解决Internet中使用的以网络为中心的安全模型的当前问题。设计的两层框架提供了语义感知机制,可以在分布式防火墙方案中执行冲突检测和策略规则的自动执行。该框架基于标准信息模型和语义感知策略语言的使用,以正式定义(然后处理)防火墙策略。研究的局限性/含义-正在进行的工作集中在识别防火墙系统中可能存在的所有类型的冲突和异常;与该任务并行的是,目前正在设计一种冲突策略的半自动解析器。实际意义-网络和安全管理员可以指定防火墙策略并对其进行验证,以发现语法和语义错误(即策略冲突)。包括一个用于在不同级别自动验证和分发策略的框架。这样可以确保防火墙策略产生所需的效果,从而有助于在一个管理域中创建和维护防火墙规则。原创性/价值-一种实用且新颖的两层系统,可检测分布式防火墙方案中存在的规则中的冲突,并自动安全地部署这些规则。提出了一种简单而强大的数据包过滤模型,用于冲突发现和规则分析过程。此外,在这种特定情况下,提出了本体和规则推理作为冲突检测问题的技术。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号