首页> 外文OA文献 >An improvement of tree-Rule firewall for a large network: supporting large rule size and low delay
【2h】

An improvement of tree-Rule firewall for a large network: supporting large rule size and low delay

机译:大型网络的树规则防火墙的改进:支持大规则大小和低延迟

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Firewalls are important network devices which provide first hand defense against network threat. This level of defense is depended on firewall rules. Traditional firewalls, i.e., Cisco ACL, IPTABLES, Check Point and Juniper NetScreen firewall use listed rule to regulate packet flows. However, the listed rules may lead to rule conflictions which make the firewall to be less secure or even slowdown in performance. Based on our previous research works, we proposed the Tree-Rule firewall which does not encounter such rule conflicts within its rule set and operates faster than the traditional firewalls. However, in big or complex networks, the Tree-Rule firewall still may face two main problems. 1. Firewall administrators may face difficulty to write big and complex rule. 2. Difficulty to select appropriate attribute column for the Root node. In this paper, we propose an improved model for the Tree-Rule firewall by extending our previous models. We offer the use of combination between IN and OUT interfaces of the firewall to separate a big rule to many small independent rules. Each separated rule then can be managed in an individual screen. Sequence of verifying attributes, i.e., Source IP, Destination IP and Destination Port numbers, can be ordered independently in each separated rule. We implement the two main schemes on Linux Cent OS 6.3. We found that the improved Tree-Rule firewall can be managed easily with low processing delay.
机译:防火墙是重要的网络设备,可提供针对网络威胁的第一手防护。此防御级别取决于防火墙规则。传统防火墙(例如Cisco ACL,IPTABLES,Check Point和Juniper NetScreen防火墙)使用列出的规则来调节数据包流。但是,列出的规则可能会导致规则冲突,从而使防火墙的安全性降低甚至降低性能。根据我们之前的研究工作,我们提出了树规则防火墙,该规则规则集不会在规则集中遇到此类规则冲突,并且比传统防火墙运行得更快。但是,在大型或复杂的网络中,Tree-Rule防火墙仍然可能面临两个主要问题。 1.防火墙管理员可能难以编写庞大而复杂的规则。 2.难以为“根”节点选择适当的属性列。在本文中,我们通过扩展先前的模型为Tree-Rule防火墙提出了一种改进的模型。我们提供防火墙的IN和OUT接口之间的组合使用,以将一个大规则与许多小的独立规则分开。然后,可以在单独的屏幕中管理每个单独的规则。验证属性的序列,即源IP,目标IP和目标端口号,可以在每个单独的规则中独立排序。我们在Linux Cent OS 6.3上实现了两个主要方案。我们发现改进的Tree-Rule防火墙可以以低处理延迟轻松管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号