基于服务分组的防火墙规则优化模型

Lin Zhang, Mengxing Huang
{"title":"基于服务分组的防火墙规则优化模型","authors":"Lin Zhang, Mengxing Huang","doi":"10.1109/WISA.2015.47","DOIUrl":null,"url":null,"abstract":"Aiming at networks with a large number of firewall rules, in order to reduce the number of rules and rule filtering times while firewall's performance does not change, a firewall policy rules merging model based on rule-service is presented. The model detects the rules in a fast way using an algorithm based on rule service first, and then it resolves the conflicts segment by using action constraint strategy. And then it runs the rule merging algorithm in a set of rules with no anomalies based on service. Finally, the experimental results show that merging efficiency is outperformed compared with other similar rule merging models. Compared to the traditional firewall, the optimized firewall model made less filtering hits while processing the same packets.","PeriodicalId":198938,"journal":{"name":"2015 12th Web Information System and Application Conference (WISA)","volume":"51 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-09-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"12","resultStr":"{\"title\":\"A Firewall Rules Optimized Model Based on Service-Grouping\",\"authors\":\"Lin Zhang, Mengxing Huang\",\"doi\":\"10.1109/WISA.2015.47\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Aiming at networks with a large number of firewall rules, in order to reduce the number of rules and rule filtering times while firewall's performance does not change, a firewall policy rules merging model based on rule-service is presented. The model detects the rules in a fast way using an algorithm based on rule service first, and then it resolves the conflicts segment by using action constraint strategy. And then it runs the rule merging algorithm in a set of rules with no anomalies based on service. Finally, the experimental results show that merging efficiency is outperformed compared with other similar rule merging models. Compared to the traditional firewall, the optimized firewall model made less filtering hits while processing the same packets.\",\"PeriodicalId\":198938,\"journal\":{\"name\":\"2015 12th Web Information System and Application Conference (WISA)\",\"volume\":\"51 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2015-09-11\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"12\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2015 12th Web Information System and Application Conference (WISA)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/WISA.2015.47\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 12th Web Information System and Application Conference (WISA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WISA.2015.47","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 12

摘要

针对具有大量防火墙规则的网络,为了在不改变防火墙性能的前提下减少规则数量和规则过滤次数,提出了一种基于规则服务的防火墙策略规则合并模型。该模型首先采用基于规则服务的算法对规则进行快速检测,然后采用动作约束策略对冲突段进行求解。然后基于服务在一组无异常的规则中运行规则合并算法。最后,实验结果表明,与同类规则合并模型相比,该算法的合并效率明显提高。与传统防火墙相比,优化后的防火墙模型在处理相同流量的情况下,过滤命中数更少。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Firewall Rules Optimized Model Based on Service-Grouping
Aiming at networks with a large number of firewall rules, in order to reduce the number of rules and rule filtering times while firewall's performance does not change, a firewall policy rules merging model based on rule-service is presented. The model detects the rules in a fast way using an algorithm based on rule service first, and then it resolves the conflicts segment by using action constraint strategy. And then it runs the rule merging algorithm in a set of rules with no anomalies based on service. Finally, the experimental results show that merging efficiency is outperformed compared with other similar rule merging models. Compared to the traditional firewall, the optimized firewall model made less filtering hits while processing the same packets.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信