An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls

碩士 === 逢甲大學 === 通訊工程學系 === 102 === Firewall is one of the premier devices of the current Internet, which can protect the entire network against attacks or threats. While configuring the firewalls, rule configuration has to conform to, or say be consistent with, the demands of the network security po...

Full description

Bibliographic Details
Main Author: 邱振添
Other Authors: 趙啟時
Format: Others
Language:zh-TW
Published: 2014
Online Access:http://ndltd.ncl.edu.tw/handle/yrzz9y
id ndltd-TW-102FCU05650005
record_format oai_dc
spelling ndltd-TW-102FCU056500052019-05-15T21:13:38Z http://ndltd.ncl.edu.tw/handle/yrzz9y An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls 以自適性異常關係樹為基底之防火牆規則異常與行為異常診斷系統 邱振添 碩士 逢甲大學 通訊工程學系 102 Firewall is one of the premier devices of the current Internet, which can protect the entire network against attacks or threats. While configuring the firewalls, rule configuration has to conform to, or say be consistent with, the demands of the network security policies so that the network security would not be flawed. Accordingly, firewall rule editing, ordering, and distribution must be done very carefully on each of the cooperative firewalls, especially in a large-scale and multi-firewall-equipped network. Nevertheless, network operators are prone to incorrectly configuring the firewalls because there are typically thousands or hundreds of thousands of filtering/admission rules (i.e., rules in the Access Control List file; or ACL for short) which could be setup in a firewall, not mention these rules among firewalls which affect mutually can make the matter worse. Under this situation, the network operators would hardly know their mis-configuration until the network functions beyond the expectations. Based on the “Adaptive Rule Anomaly Relation Tree (Adaptive RAR)”, thesis will speed up the system to detect these anomalies for reasonable time consumption, and balance the cost of online security analysis cost and efficiency. It uses the geometry correlation of firewall rules, and constructs the Adaptive RAR tree-based data structure that reuse the local diagnosis results to diagnosis the anomalies among firewalls. It can reduce time or space consumption between rule comparison when the number of the firewalls, rules and rule conditions becomes huge. It will protect the firewall system to avoid accidents, and come to defense in depth 趙啟時 2014 學位論文 ; thesis 56 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 逢甲大學 === 通訊工程學系 === 102 === Firewall is one of the premier devices of the current Internet, which can protect the entire network against attacks or threats. While configuring the firewalls, rule configuration has to conform to, or say be consistent with, the demands of the network security policies so that the network security would not be flawed. Accordingly, firewall rule editing, ordering, and distribution must be done very carefully on each of the cooperative firewalls, especially in a large-scale and multi-firewall-equipped network. Nevertheless, network operators are prone to incorrectly configuring the firewalls because there are typically thousands or hundreds of thousands of filtering/admission rules (i.e., rules in the Access Control List file; or ACL for short) which could be setup in a firewall, not mention these rules among firewalls which affect mutually can make the matter worse. Under this situation, the network operators would hardly know their mis-configuration until the network functions beyond the expectations. Based on the “Adaptive Rule Anomaly Relation Tree (Adaptive RAR)”, thesis will speed up the system to detect these anomalies for reasonable time consumption, and balance the cost of online security analysis cost and efficiency. It uses the geometry correlation of firewall rules, and constructs the Adaptive RAR tree-based data structure that reuse the local diagnosis results to diagnosis the anomalies among firewalls. It can reduce time or space consumption between rule comparison when the number of the firewalls, rules and rule conditions becomes huge. It will protect the firewall system to avoid accidents, and come to defense in depth
author2 趙啟時
author_facet 趙啟時
邱振添
author 邱振添
spellingShingle 邱振添
An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
author_sort 邱振添
title An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
title_short An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
title_full An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
title_fullStr An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
title_full_unstemmed An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
title_sort adaptive rar tree-based diagnosis system for rule anomalies and behavior mismatching among network firewalls
publishDate 2014
url http://ndltd.ncl.edu.tw/handle/yrzz9y
work_keys_str_mv AT qiūzhèntiān anadaptiverartreebaseddiagnosissystemforruleanomaliesandbehaviormismatchingamongnetworkfirewalls
AT qiūzhèntiān yǐzìshìxìngyìchángguānxìshùwèijīdǐzhīfánghuǒqiángguīzéyìchángyǔxíngwèiyìchángzhěnduànxìtǒng
AT qiūzhèntiān adaptiverartreebaseddiagnosissystemforruleanomaliesandbehaviormismatchingamongnetworkfirewalls
_version_ 1719110671198584832