首页> 外国专利> METHOD AND APPARATUS FOR ANALYZING ONE OR MORE FIREWALLS

METHOD AND APPARATUS FOR ANALYZING ONE OR MORE FIREWALLS

机译:用于分析一个或多个防火墙的方法和装置

摘要

A method and apparatus are disclosed for analyzing the operation of one or more network gateways, such as firewalls or routers, that perform a packet filtering function in a network environment. Given a user query, the disclosed firewall analysis tool simulates the behavior of the various firewalls, taking into account the topology of the network environment, and determines which portions of the services or machines specified in the original query would manage to reach from the source to the destination. The relevant packet-filtering configuration files are collected and an internal representation of the implied security policy is derived. A graph data structure is used to represent the network topology. A gateway-zone graph permits the firewall analysis tool to determine where given packets will travel in the network, and which gateways will be encountered along those paths. In this manner, the firewall analysis tool can evaluate a query object against each rule-base object, for each gateway node in the gateway-zone graph that is encountered along each path between the source and destination. A graphical user interface is provided for receiving queries, such as whether one or more given services are permitted between one or more given machines, and providing results. A spoofing attack can be simulated by allowing the user to specify where packets are to be injected into the network, which may not be the true location of the source host-group.
机译:公开了一种用于分析在网络环境中执行分组过滤功能的一个或多个网络网关(例如防火墙或路由器)的操作的方法和装置。给定用户查询,所公开的防火墙分析工具会考虑网络环境的拓扑,模拟各种防火墙的行为,并确定原始查询中指定的服务或计算机的哪些部分将设法从源到达目的地。收集相关的数据包筛选配置文件,并派生隐含安全策略的内部表示。图形数据结构用于表示网络拓扑。网关区域图允许防火墙分析工具确定给定的数据包在网络中的传播位置,以及沿着这些路径遇到的网关。以这种方式,防火墙分析工具可以针对沿着源与目的地之间的每个路径遇到的网关区域图中的每个网关节点,针对每个规则库对象评估一个查询对象。提供了一种图形用户界面,用于接收查询,例如在一个或多个给定机器之间是否允许一个或多个给定服务,并提供结果。可以通过允许用户指定将数据包注入网络的位置来模拟欺骗攻击,这可能不是源主机组的真实位置。

著录项

  • 公开/公告号CA2328012C

    专利类型

  • 公开/公告日2007-05-15

    原文格式PDF

  • 申请/专利权人 LUCENT TECHNOLOGIES INC.;

    申请/专利号CA20002328012

  • 申请日2000-12-12

  • 分类号H04L12/26;H04L12/24;H04L12/66;H04L29/06;

  • 国家 CA

  • 入库时间 2022-08-21 20:54:08

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号