...
首页> 外文期刊>電子情報通信学会技術研究報告 >BISCAL: Bit Vector Based Spatial Calculus for Analyzing the Mis-configurations in Firewall Policies
【24h】

BISCAL: Bit Vector Based Spatial Calculus for Analyzing the Mis-configurations in Firewall Policies

机译:BISCAL:基于位向量的空间演算,用于分析防火墙策略中的错误配置

获取原文
获取原文并翻译 | 示例
           

摘要

Packet filtering in firewalls operates at the network level of the OSI model, or the IP layer of TCP/IP. In a packet filtering each packet is compared to a set of conditions before it is forwarded. Depending on the header of the packet, the firewall accepts or denies the packet. Since business needs are dynamic, firewall policies are constantly being changed and modified. Firewall administration teams in large organizations often process dozens of filter additions and changes daily. This continuous flux causes the firewall configuration to grow dramatically over time. A huge and, subsequently complex, firewall configuration is hard to manage and may require lengthy research in order to add or change a filter and results in mis-configurations in firewall policies. Powerful error classification method was proposed based upon the geometrical interpretation of policies in order to detect such mis-configurations in firewall policies. However, as the filters and key fields of the header increase, it demands high memory and computation time. We propose a topological approach called BISCAL (Bit-vector based spatial calculus) to detect the conflicts in the firewall policles to solve this problem.
机译:防火墙中的数据包筛选在OSI模型的网络级别或TCP / IP的IP层上运行。在数据包过滤中,每个数据包在转发之前都会与一组条件进行比较。根据数据包的标头,防火墙接受还是拒绝数据包。由于业务需求是动态的,因此防火墙策略不断地被更改和修改。大型组织中的防火墙管理团队经常每天处理数十个过滤器添加和更改。这种持续不断的变化会导致防火墙配置随时间急剧增长。庞大且随后复杂的防火墙配置难以管理,可能需要进行长时间的研究才能添加或更改过滤器,并导致防火墙策略中的配置错误。为了检测防火墙策略中的此类错误配置,基于策略的几何解释提出了一种强大的错误分类方法。但是,随着标头的过滤器和关键字段的增加,它需要大量的内存和计算时间。我们提出一种称为BISCAL(基于位向量的空间演算)的拓扑方法,以检测防火墙策略中的冲突以解决此问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号