An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls
碩士 === 逢甲大學 === 通訊工程學系 === 102 === Firewall is one of the premier devices of the current Internet, which can protect the entire network against attacks or threats. While configuring the firewalls, rule configuration has to conform to, or say be consistent with, the demands of the network security po...
Main Author: | |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2014
|
Online Access: | http://ndltd.ncl.edu.tw/handle/yrzz9y |
id |
ndltd-TW-102FCU05650005 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-102FCU056500052019-05-15T21:13:38Z http://ndltd.ncl.edu.tw/handle/yrzz9y An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls 以自適性異常關係樹為基底之防火牆規則異常與行為異常診斷系統 邱振添 碩士 逢甲大學 通訊工程學系 102 Firewall is one of the premier devices of the current Internet, which can protect the entire network against attacks or threats. While configuring the firewalls, rule configuration has to conform to, or say be consistent with, the demands of the network security policies so that the network security would not be flawed. Accordingly, firewall rule editing, ordering, and distribution must be done very carefully on each of the cooperative firewalls, especially in a large-scale and multi-firewall-equipped network. Nevertheless, network operators are prone to incorrectly configuring the firewalls because there are typically thousands or hundreds of thousands of filtering/admission rules (i.e., rules in the Access Control List file; or ACL for short) which could be setup in a firewall, not mention these rules among firewalls which affect mutually can make the matter worse. Under this situation, the network operators would hardly know their mis-configuration until the network functions beyond the expectations. Based on the “Adaptive Rule Anomaly Relation Tree (Adaptive RAR)”, thesis will speed up the system to detect these anomalies for reasonable time consumption, and balance the cost of online security analysis cost and efficiency. It uses the geometry correlation of firewall rules, and constructs the Adaptive RAR tree-based data structure that reuse the local diagnosis results to diagnosis the anomalies among firewalls. It can reduce time or space consumption between rule comparison when the number of the firewalls, rules and rule conditions becomes huge. It will protect the firewall system to avoid accidents, and come to defense in depth 趙啟時 2014 學位論文 ; thesis 56 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 逢甲大學 === 通訊工程學系 === 102 === Firewall is one of the premier devices of the current Internet, which can protect the entire network against attacks or threats. While configuring the firewalls, rule configuration has to conform to, or say be consistent with, the demands of the network security policies so that the network security would not be flawed. Accordingly, firewall rule editing, ordering, and distribution must be done very carefully on each of the cooperative firewalls, especially in a large-scale and multi-firewall-equipped network. Nevertheless, network operators are prone to incorrectly configuring the firewalls because there are typically thousands or hundreds of thousands of filtering/admission rules (i.e., rules in the Access Control List file; or ACL for short) which could be setup in a firewall, not mention these rules among firewalls which affect mutually can make the matter worse. Under this situation, the network operators would hardly know their mis-configuration until the network functions beyond the expectations.
Based on the “Adaptive Rule Anomaly Relation Tree (Adaptive RAR)”, thesis will speed up the system to detect these anomalies for reasonable time consumption, and balance the cost of online security analysis cost and efficiency. It uses the geometry correlation of firewall rules, and constructs the Adaptive RAR tree-based data structure that reuse the local diagnosis results to diagnosis the anomalies among firewalls. It can reduce time or space consumption between rule comparison when the number of the firewalls, rules and rule conditions becomes huge. It will protect the firewall system to avoid accidents, and come to defense in depth
|
author2 |
趙啟時 |
author_facet |
趙啟時 邱振添 |
author |
邱振添 |
spellingShingle |
邱振添 An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls |
author_sort |
邱振添 |
title |
An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls |
title_short |
An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls |
title_full |
An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls |
title_fullStr |
An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls |
title_full_unstemmed |
An Adaptive RAR Tree-Based Diagnosis System for Rule Anomalies and Behavior Mismatching among Network Firewalls |
title_sort |
adaptive rar tree-based diagnosis system for rule anomalies and behavior mismatching among network firewalls |
publishDate |
2014 |
url |
http://ndltd.ncl.edu.tw/handle/yrzz9y |
work_keys_str_mv |
AT qiūzhèntiān anadaptiverartreebaseddiagnosissystemforruleanomaliesandbehaviormismatchingamongnetworkfirewalls AT qiūzhèntiān yǐzìshìxìngyìchángguānxìshùwèijīdǐzhīfánghuǒqiángguīzéyìchángyǔxíngwèiyìchángzhěnduànxìtǒng AT qiūzhèntiān adaptiverartreebaseddiagnosissystemforruleanomaliesandbehaviormismatchingamongnetworkfirewalls |
_version_ |
1719110671198584832 |