{"title":"一种可行的状态防火墙规则异常诊断机制","authors":"C. Chao","doi":"10.1109/ICCCN.2018.8487390","DOIUrl":null,"url":null,"abstract":"Configuring firewalls is no easy task because typically there are hundreds of thousands of filtering rules (i.e., rules in the Access Control List file; or ACL for short) which could be set up in firewalls, and these rules can affect mutually. Based on the success of our previous work on anomaly diagnosis in firewall rules, this paper describes our newly developed diagnosis mechanisms which can speedily discover anomalies of stateful rules within/among firewalls with an innovative data structure - Enhanced Adaptive Rule Anomaly Relationship (or Enhanced-ARAR) tree. With the assistance of the data structure and associated algorithms, our developed system prototype shows its feasibility and efficiency in anomaly diagnosis for stateful Internet firewalls.","PeriodicalId":399145,"journal":{"name":"2018 27th International Conference on Computer Communication and Networks (ICCCN)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"A Feasible Anomaly Diagnosis Mechanism for Stateful Firewall Rules\",\"authors\":\"C. Chao\",\"doi\":\"10.1109/ICCCN.2018.8487390\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Configuring firewalls is no easy task because typically there are hundreds of thousands of filtering rules (i.e., rules in the Access Control List file; or ACL for short) which could be set up in firewalls, and these rules can affect mutually. Based on the success of our previous work on anomaly diagnosis in firewall rules, this paper describes our newly developed diagnosis mechanisms which can speedily discover anomalies of stateful rules within/among firewalls with an innovative data structure - Enhanced Adaptive Rule Anomaly Relationship (or Enhanced-ARAR) tree. With the assistance of the data structure and associated algorithms, our developed system prototype shows its feasibility and efficiency in anomaly diagnosis for stateful Internet firewalls.\",\"PeriodicalId\":399145,\"journal\":{\"name\":\"2018 27th International Conference on Computer Communication and Networks (ICCCN)\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-07-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 27th International Conference on Computer Communication and Networks (ICCCN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCCN.2018.8487390\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 27th International Conference on Computer Communication and Networks (ICCCN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCCN.2018.8487390","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
A Feasible Anomaly Diagnosis Mechanism for Stateful Firewall Rules
Configuring firewalls is no easy task because typically there are hundreds of thousands of filtering rules (i.e., rules in the Access Control List file; or ACL for short) which could be set up in firewalls, and these rules can affect mutually. Based on the success of our previous work on anomaly diagnosis in firewall rules, this paper describes our newly developed diagnosis mechanisms which can speedily discover anomalies of stateful rules within/among firewalls with an innovative data structure - Enhanced Adaptive Rule Anomaly Relationship (or Enhanced-ARAR) tree. With the assistance of the data structure and associated algorithms, our developed system prototype shows its feasibility and efficiency in anomaly diagnosis for stateful Internet firewalls.