首页> 外文期刊>International Journal of Information Security >Detection of firewall configuration errors with updatable tree
【24h】

Detection of firewall configuration errors with updatable tree

机译:使用可更新的树检测防火墙配置错误

获取原文
获取原文并翻译 | 示例
           

摘要

The fundamental goals of security policy are to allow uninterrupted access to the network resources for authenticated users and to deny access to unauthenticated users. For this purpose, firewalls are frequently deployed in every size network. However, bad configurations may cause serious security breaches and network vulnerabilities. In particular, conflicted filtering rules lead to block legitimate traffic and to accept unwanted packets. This fact troubles administrators who have to insert and delete filtering rules in a huge configuration file. We propose in this paper a quick method for managing a firewall configuration file. We represent the set of filtering rules by a firewall anomaly tree (FAT). Then, an administrator can update the FAT by inserting and deleting some filtering rules. The FAT modification automatically reveals emerged anomalies and helps the administrator to find the adequate position for a new added filtering rule. All the algorithms presented in the paper have been implemented, and computer experiments show the usefulness of updating the FAT data structure in order to quickly detect anomalies when dealing with a huge firewall configuration file.
机译:安全策略的基本目标是允许经过身份验证的用户不间断访问网络资源,并拒绝对未经身份验证的用户进行访问。为此,防火墙经常部署在各种规模的网络中。但是,不良的配置可能会导致严重的安全漏洞和网络漏洞。特别是,冲突的过滤规则会导致阻止合法流量并接受不需要的数据包。这使必须在庞大的配置文件中插入和删除过滤规则的管理员感到困扰。我们在本文中提出了一种管理防火墙配置文件的快速方法。我们用防火墙异常树(FAT)表示过滤规则集。然后,管理员可以通过插入和删除一些过滤规则来更新FAT。 FAT修改会自动发现出现的异常,并帮助管理员找到适合新添加的过滤规则的位置。本文中介绍的所有算法均已实现,计算机实验表明,在处理庞大的防火墙配置文件时,更新FAT数据结构以快速检测异常的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号