Computer Science ›› 2013, Vol. 40 ›› Issue (3): 50-54.
Previous Articles Next Articles
Online:
Published:
Abstract: Firewalls arc playing a very important role in network security, because the firewall policy rules arc determining that the network packet "Allow" or "Rejected" out of network. For the large networks,the rules are too many to ensure they have not conflict, therefore the detection and resolution of the policy conflict become an important aspect of network security. This paper presented a parallel method of firewall policy conflict detection and resolution algorithm,which resorts the segments formed by the rule-based segmentation technology, and translates the segments into the form of rules, uses this new rules instead of the original rules for packet filtering. Because all segments arc pairwise dis- jointed and every segment has one action, the conflicts in policy arc resolved.
Key words: Rules, Confliction, Segment, Action, Ordering
0 / / Recommend
Add to citation manager EndNote|Reference Manager|ProCite|BibTeX|RefWorks
URL: https://www.jsjkx.com/EN/
https://www.jsjkx.com/EN/Y2013/V40/I3/50
Cited