首页 | 官方网站   微博 | 高级检索  
     

基于改进策略树的防火墙策略审计方案设计与实现
引用本文:卢云龙,罗守山,郭玉鹏.基于改进策略树的防火墙策略审计方案设计与实现[J].信息网络安全,2014(10):64-69.
作者姓名:卢云龙  罗守山  郭玉鹏
作者单位:1. 北京邮电大学信息安全中心,北京,100876
2. 北京林业大学信息学院,北京,100083
基金项目:国家自然科学基金[61121061、61161140320]、国家电网科学计划[EPRIXXKJ
摘    要:防火墙在当今网络中起着不可或缺的作用,防火墙规则配置的合理与否直接关系到网络环境的安全.随着网络规模日益增大,防火墙配置也日趋复杂,为了更好的发挥防火墙的防护性能,防火墙策略审计应需而生.文章首先对防火墙规则之间的关系进行了详细研究,总结并分析了一些常见的规则异常种类,并对现有的策略审计方案进行了综述研究.其次,论述了防火墙策略审计系统整体的工作流程,层次化的分析了系统总体架构设计,对防火墙策略审计系统的配置规则审计模块进行了重点研究论述.再次,论述了传统的策略判定树审计方案,详细阐述了该方案的实现流程,分析并指出了该方案的优点以及所存在的不足.接下来提出一种以树形结构为基础改进后的策略审计方案,详细论述了该方案的审计流程并实现了改进的审计方案.最后结合该实现展示了系统的图形化报表以及详细审计结果,对改进后审计方案的审计结果与传统策略树进行了对比分析验证.

关 键 词:防火墙  规则关系  策略树  冲突异常  审计

The Design and Implementation of Firewall Policy Audit Plan Based on Improved Strategy Tree
LU Yun-long,LUO Shou-shan,GUO Yu-peng.The Design and Implementation of Firewall Policy Audit Plan Based on Improved Strategy Tree[J].Netinfo Security,2014(10):64-69.
Authors:LU Yun-long  LUO Shou-shan  GUO Yu-peng
Affiliation:LU Yun-long, LUO Shou-shan, GUO Yu-peng (1. Information Security Center, Beij'ing University of Posts and Telecommunications, Beijing 100876, China; 2. School of Information Science & Technology, Beijing Forestry University, Beijing 100083, China)
Abstract:The firewall plays an indispensable role in today's network; the configuration of the fircwall rules is directly related to the security of the network environment. As the network scale increases, the firewall configuration becomes more complex, in order to improve the protective performance of firewall, the firewall policy audit needs to be applied. At first, this paper researches on the relationship between the firewall rules in detail, summarizes and analyzes some common exception types of rules, and the strategies of the existing audit plan are reviewed. Secondly, this paper discusses the whole working process of the firewall policy audit system, hierarchically analyzes the overall design of the system architecture. Then the configuration rules audit module of the firewall policy audit system is discussed emphatically. Again, this paper discusses the traditional strategy decision tree audit plan, expounds the realization process of the scheme, analyzes and points out the merit and the deficiency of the scheme. Then we put forward an improved audit plan based on the tree structure strategy, discuss the audit process of the scheme in detail and implement the audit plan. Finally we give the graphical reports and detailed audit results of the system, after which we analyze the two by comparing the improved audit plan to the traditional strategy tree.
Keywords:firewall  roles relationship  policy tree  conflict  audit
本文献已被 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司    京ICP备09084417号-23

京公网安备 11010802026262号