首页> 美国政府科技报告 >Static Reachability Analysis and Validation Regarding Security Policies Implemented via Packet Filters
【24h】

Static Reachability Analysis and Validation Regarding Security Policies Implemented via Packet Filters

机译:关于通过包过滤器实现的安全策略的静态可达性分析和验证

获取原文

摘要

The ability to statically determine what kinds of packets can be exchanged between two hosts on a network is desirable to those who design and operate networks but this is a difficult and complex problem. Factors affecting reachability analysis are packet filters routing policies and packet transformations. The number of variables within and among networks is intractable for manual computation. A proposed solution to this mess is a tractable framework for which to map networks into thus creating a single unified model for analysis. It depends heavily on the use of transforming the problem into a classical graph problem that can be solved with polynomial time algorithms such as transitive closure. This research develops an automated validation process to test the reachability upper bound calculated from a recent implementation of the framework which focuses specifically on the packet filter aspect namely access control lists. Real-world network configuration files and network packet flow data from a Tier-i Internet Service Provider is supplied as the data set. A significant contribution of this thesis is the application of real-world data to the proposed method for static reachability analysis as it pertains to the static testing of security policies applied via packet filters.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号