跳到主要导航 跳到搜索 跳到主要内容

Modeling and global conflict analysis of firewall policy

  • Xiaoyan Liang
  • , Chunhe Xia*
  • , Jian Jiao
  • , Junshun Hu
  • , Xiaojian Li
  • *此作品的通讯作者
  • Beihang University
  • Beijing Information Science, Technology University
  • Software Development Center of China Agricultural Bank
  • Guangxi Normal University

科研成果: 期刊稿件文章同行评审

摘要

The global view of firewall policy conflict is important for administrators to optimize the policy. It has been lack of appropriate firewall policy global conflict analysis, existing methods focus on local conflict detection. We research the global conflict detection algorithm in this paper. We presented a semantic model that captures more complete classifications of the policy using knowledge concept in rough set. Based on this model, we presented the global conflict formal model, and represent it with OBDD (Ordered Binary Decision Diagram). Then we developed GFPCDA (Global Firewall Policy Conflict Detection Algorithm) algorithm to detect global conflict. In experiment, we evaluated the usability of our semantic model by eliminating the false positives and false negatives caused by incomplete policy semantic model, of a classical algorithm. We compared this algorithm with GFPCDA algorithm. The results show that GFPCDA detects conflicts more precisely and independently, and has better performance.

源语言英语
文章编号6880468
页(从-至)124-135
页数12
期刊China Communications
11
5
DOI
出版状态已出版 - 2014

指纹

探究 'Modeling and global conflict analysis of firewall policy' 的科研主题。它们共同构成独一无二的指纹。

引用此