计算机科学 ›› 2013, Vol. 40 ›› Issue (3): 50-54.

• 2012多值逻辑专栏 • 上一篇    下一篇

一种基于MapReduce的防火墙策略冲突并行化检测及消解模型

肖 淇,秦云川,阳王东,李肯立   

  1. (湖南大学信息科学与工程学院 长沙410082)
  • 出版日期:2018-11-16 发布日期:2018-11-16

MapReduce-based Parallelization Model for Firewall Policy Conflict Detecting and Resolving

  • Online:2018-11-16 Published:2018-11-16

摘要: 防火墙在网络安全中起到很重要的作用,其中防火墙策略中的规则决定了网络数据包被“允许”或被“拒绝”进出网络。对于大型网络来说,由于规则太多,管理者很难保证其中不出现冲突,因此策略中规则冲突的检测及解决成为了保证网络安全的重要方面。提出了一种基于MapReduce模型的防火墙策略冲突检测解决算法,它对由基于规则的分段技术得到的片段进行自定义的排序,之后将其转化为规则的形式来代替原来的规则进行数据包的过滤。片段间两两不相交且匹配的包只执行一种动作,从而消除了冲突。

关键词: 防火墙,规则冲突,分段,动作,排序

Abstract: Firewalls arc playing a very important role in network security, because the firewall policy rules arc determining that the network packet "Allow" or "Rejected" out of network. For the large networks,the rules are too many to ensure they have not conflict, therefore the detection and resolution of the policy conflict become an important aspect of network security. This paper presented a parallel method of firewall policy conflict detection and resolution algorithm,which resorts the segments formed by the rule-based segmentation technology, and translates the segments into the form of rules, uses this new rules instead of the original rules for packet filtering. Because all segments arc pairwise dis- jointed and every segment has one action, the conflicts in policy arc resolved.

Key words: Rules, Confliction, Segment, Action, Ordering

No related articles found!
Viewed
Full text


Abstract

Cited

  Shared   
  Discussed   
No Suggested Reading articles found!