Analysis Methods of Firewall Policies by using Spatial Relationships between Filters

Y. Yin, R. Bhuvaneswaran, Y. Katayama, N. Takahashi
{"title":"Analysis Methods of Firewall Policies by using Spatial Relationships between Filters","authors":"Y. Yin, R. Bhuvaneswaran, Y. Katayama, N. Takahashi","doi":"10.1109/ICSCN.2007.350761","DOIUrl":null,"url":null,"abstract":"Network security can be increased by filtering packets at a firewall. Packet filtering examines network packets and decides whether to accept or deny them, and these decisions are made according to policies that are established by the network administrator and implemented by specific filters. An administrator who finds it hard to understand and maintain a policy, will not easily find problems that occur when the filters are changed (added, deleted, or replaced) or when hierarchical firewalls are used and will therefore not be certain that the intended policies are implemented correctly and completely. In this paper, we consider the relations of filters as spatial relations, and propose three analysis methods (impact inferring, equality judgment, and composition analysis) to determine anomalies of firewall policies by using spatial relations between filters","PeriodicalId":257948,"journal":{"name":"2007 International Conference on Signal Processing, Communications and Networking","volume":"2012 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2007-11-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2007 International Conference on Signal Processing, Communications and Networking","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSCN.2007.350761","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Network security can be increased by filtering packets at a firewall. Packet filtering examines network packets and decides whether to accept or deny them, and these decisions are made according to policies that are established by the network administrator and implemented by specific filters. An administrator who finds it hard to understand and maintain a policy, will not easily find problems that occur when the filters are changed (added, deleted, or replaced) or when hierarchical firewalls are used and will therefore not be certain that the intended policies are implemented correctly and completely. In this paper, we consider the relations of filters as spatial relations, and propose three analysis methods (impact inferring, equality judgment, and composition analysis) to determine anomalies of firewall policies by using spatial relations between filters
基于过滤器空间关系的防火墙策略分析方法
通过在防火墙对数据包进行过滤,可以提高网络安全性。包过滤对网络数据包进行检测,并根据网络管理员制定的策略决定是否接受或拒绝这些数据包,这些策略由特定的过滤器实现。如果管理员很难理解和维护策略,那么在更改过滤器(添加、删除或替换)或使用分层防火墙时,就不容易发现出现的问题,因此无法确定预期的策略是否得到了正确和完整的实现。本文将过滤器之间的关系视为空间关系,提出了三种分析方法(影响推断、相等性判断和成分分析),利用过滤器之间的空间关系来判断防火墙策略的异常
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信