ACLA: A framework for Access Control List (ACL) Analysis and Optimization

ACLA: A framework for Access Control List (ACL) Analysis and Optimization
复制标题

ACLA:访问控制列表 (ACL) 分析和优化的框架

DOI:
10.1007/978-0-387-35413-2_18
复制
发表时间:
2001
影响因子:
16.4
通讯作者:
J. Qian
J. Qian
中科院分区:
计算机科学1区
文献类型:
--
作者:
J. Qian

文献摘要

被引文献

相似文献

It is a challenging task for network administrators to correctly implement corporate security policies in a large network environment. Much of the security policy enforcement at the network level involves configuring the packet classification strategies using Access Control List (ACL). A gateway device performing traffic filtering can deploy ACLs with thousands of rules. Due to the difficulties of ACL configuration language, large ACLs can easily become redundant, inconsistent, and difficult to optimise or even understand. This problem is augmented by extrinsic factors such as administrator turnovers, unstructured and ill-planned topology changes. With multiple routers in the topology, all of the ACLs need to be configured in a consistent manner to enforce the corporate security policy. In such an environment, manual examination of ACLs to ensure security policy is implemented correctly is a nearly impossible task.