计算机应用与软件
計算機應用與軟件
계산궤응용여연건
Computer Applications and Software
2015年
8期
292-295
,共4页
多防火墙%规则集%启发式方法%路由
多防火牆%規則集%啟髮式方法%路由
다방화장%규칙집%계발식방법%로유
Multi-firewall%Rule sets%Heuristic solution%Route
当防火墙的规则集规模增加的时候,防火墙的复杂性被认为是增加的。实证研究表明,随着规则集的增大,防火墙配置错误的数量在急剧增加,而防火墙的性能会降低。当设计一个安全敏感的网络时,为了减少防火墙规则集的规模,关键是仔细构建网络拓扑及其路由结构,它有助于降低安全漏洞的机会,避免性能瓶颈。针对如何在网络的拓扑设计和构建路由表操作期间的最小化最大多防火墙规则集,提出一个启发式的解决方案。运用仿真对算法的实效性进行证明。仿真试验结果显示,该算法相比于别类算法降低了多防火墙规则集的规模。
噹防火牆的規則集規模增加的時候,防火牆的複雜性被認為是增加的。實證研究錶明,隨著規則集的增大,防火牆配置錯誤的數量在急劇增加,而防火牆的性能會降低。噹設計一箇安全敏感的網絡時,為瞭減少防火牆規則集的規模,關鍵是仔細構建網絡拓撲及其路由結構,它有助于降低安全漏洞的機會,避免性能瓶頸。針對如何在網絡的拓撲設計和構建路由錶操作期間的最小化最大多防火牆規則集,提齣一箇啟髮式的解決方案。運用倣真對算法的實效性進行證明。倣真試驗結果顯示,該算法相比于彆類算法降低瞭多防火牆規則集的規模。
당방화장적규칙집규모증가적시후,방화장적복잡성피인위시증가적。실증연구표명,수착규칙집적증대,방화장배치착오적수량재급극증가,이방화장적성능회강저。당설계일개안전민감적망락시,위료감소방화장규칙집적규모,관건시자세구건망락탁복급기로유결구,타유조우강저안전루동적궤회,피면성능병경。침대여하재망락적탁복설계화구건로유표조작기간적최소화최대다방화장규칙집,제출일개계발식적해결방안。운용방진대산법적실효성진행증명。방진시험결과현시,해산법상비우별류산법강저료다방화장규칙집적규모。
The complexity of firewall is known to increase along with the increase of its rule set size.Empirical studies show that as the rule set growing larger, the number of configuration errors on a firewall increases sharply, while the performance of the firewall degrades. When designing a security-sensitive network, it is critical to construct the network topology and its routing structure carefully in order to re-duce the size of firewall rule sets, which helps lower the chance of security loopholes and prevent performance bottleneck.This paper presents a heuristic solution for the problem of how the maximum multi-firewall rule set can be minimised during the topology design of network and during the operation of routing tables'construction.By simulations we prove the effectiveness of the algorithm.Simulation testing results show that the proposed algorithm reduces the size of multi-firewall rule set comparing with other algorithms.