防火墙策略建模与其全局冲突分析(英文)

来源 :中国通信 | 被引量 : 0次 | 上传用户:liongliong434
下载到本地 , 更方便阅读
声明 : 本文档内容版权归属内容提供方 , 如果您对本文有版权争议 , 可与客服联系进行内容授权或下架
论文部分内容阅读
The global view of firewall policy conflict is important for administrators to optimize the policy.It has been lack of appropriate firewall policy global conflict analysis,existing methods focus on local conflict detection.We research the global conflict detection algorithm in this paper.We presented a semantic model that captures more complete classifications of the policy using knowledge concept in rough set.Based on this model,we presented the global conflict formal model,and represent it with OBDD(Ordered Binary Decision Diagram).Then we developed GFPCDA(Global Firewall Policy Conflict Detection Algorithm) algorithm to detect global conflict.In experiment,we evaluated the usability of our semantic model by eliminating the false positives and false negatives caused by incomplete policy semantic model,of a classical algorithm.We compared this algorithm with GFPCDA algorithm.The results show that GFPCDA detects conflicts more precisely and independently,and has better performance. The global view of firewall policy conflict is important for for administrators to optimize the policy. It has been lack of appropriate firewall policy global conflict analysis, existing methods focus on local conflict detection. We research the global conflict detection algorithm in this paper. We presented a semantic model that captures more complete classifications of the policy using knowledge concept in rough set.Based on this model, we presented the global conflict formal model, and represent it with OBDD (Ordered Binary Decision Diagram) .Then we developed GFPCDA (Global Firewall Policy Conflict Detection Algorithm) algorithm to detect global conflict.In experiment, we evaluated the usability of our semantic model by eliminating the false positives and false negatives caused by incomplete policy semantic model, of a classical algorithm. We compared this algorithm with GFPCDA algorithm. results show that GFPCDA detects conflicts more precisely and independently, and has better performance.
其他文献
在分析无源质心干扰反舰导弹特征的基础,建立了干扰的仿真数学模型,并通过实例计算,结果分析,对模型进行了检验。
推导几种使用条件下的有源雷达诱饵的干扰方程,分析了实现投掷式有源雷达诱饵的技术可行性,针对典型实用情况计算了诱饵的总体参数。
2008年10月24日下午4时,日本前首相中曾根康弘莅临上海交通大学徐汇校区,参加国际与公共事务学院成立五周年庆典活动,在接受上海交通大学名誉教授授予仪式上,发表了《亚洲的未来
结合自己多年在国内建筑施工企业的工作经验,分析了施工企业工程项目面临的各种风险,建立了建筑施工企业工程项目风险理论体系和管理模式,全面分析和阐述了风险规划、识别、评估
改革破除了平均主义'大锅饭',却又出现收入的贫富悬殊,并引发出一系列社会矛盾与问题.在市场经济环境下,收入差距与拉大有其制度与政策原因,也与转轨期体制的某些真
黄部长说,“总的感觉是阳泉矿务局搞得不错。你们的困难是带普遍性的.关键的问题.一是在投资方面要把现有的钱用好,不建勋已,要建就要很快建成,不能一拖七、
随着经济发展,市场需求对电力输送的要求日渐提高,专业、迅速的电力抢修成为电网运行检修的必备条件,本文从电力抢修系统中信号及时准确接收与传输的角度出发,提出了一种基于
通过多元素分析,物相分析,扫描电子显微镜等检测,发现镍钼矿中的钼主要赋存于胶硫钼矿中,S∶Mo原子个数比介于2.72~2.94之间,且胶硫钼矿与黄铁矿,镍黄铁矿共生关系密切。通过
张锦程先生,系泰国顺和成集团、泰国亿王亚哥大众公司创始董事长。<br>  张锦程先生祖籍普宁泥沟村,出生于泰国北柳府,旅泰著名侨领。他致力经营农产品,多年来对繁荣泰国经济的
期刊
提出一种基于采样过程频谱复制特性的信号合成技术。这一技术采用二阶带通采样在各信号元素间提供相位控制。尽管这种相位控制在信号间并不独立,而且还将受到幅度衰减的限制,但