首页> 外国专利> detection of abnormalities in the semantic rules for filtering firewalls

detection of abnormalities in the semantic rules for filtering firewalls

机译:检测用于过滤防火墙的语义规则中的异常

摘要

firewalls are physical or logical computing devices provide the interface between two or more networks in order to control the flow of packets through the tcp / ip there. to do so, they are based on a list of rules for filtering on the security policy is applied.however, the list of rules for filtering, due to configuration errors, can understand the anomalies. this patent provides a new classification of anomalies between the rules of screening; there are, in fact, between the syntactic and semantic anomalies anomalies.the syntactic anomaly is defined as the generation of errors in the filtering rules with inconsistency and conflict between the response of the firewall and security policy is needed.semantic anomalies, the present invention defines and proves the existence of the security logic flaws, which may exist in a filtering rule, or a combination of various standards and can be used by an intruder to attack it in use a legitimate data flows. the semantic anomaly detection, therefore, is a crucial and urgent task.in addition, it can strengthen security at the border of the network, to block the maximum attempted attacks based on tcp / ip packet handling, ease of intrusion sensors and probes, balancing the load between all systems security is made and, therefore, the high speed growing.
机译:防火墙是物理或逻辑计算设备,它在两个或多个网络之间提供接口,以控制通过tcp / ip的数据包流。这样做,它们是基于对安全策略应用的过滤规则列表。但是,由于配置错误,过滤规则列表可以理解异常。该专利提供了筛选规则之间异常的新分类;实际上,在语法异常和语义异常之间存在。语法异常被定义为过滤规则中的错误的产生,该错误具有不一致,并且防火墙的响应与安全策略之间需要冲突。语义异常,本发明定义并证明安全逻辑缺陷的存在,这些缺陷可能存在于过滤规则中,也可能存在于各种标准的组合中,并且可以被入侵者使用合法数据流对其进行攻击。因此,语义异常检测是一项紧迫而紧迫的任务。此外,它可以增强网络边界的安全性,基于tcp / ip数据包处理来阻止最大的尝试攻击,并简化入侵传感器和探测,平衡了所有系统之间的负载安全性,因此,高速增长。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号