Simultaneous Analysis of Time and Space for Conflict Detection in Time-Based Firewall Policies

Simultaneous Analysis of Time and Space for Conflict Detection in Time-Based Firewall Policies
复制标题

基于时间的防火墙策略中冲突检测的时间和空间同步分析

DOI:
10.1109/cit.2010.186
复制
发表时间:
2010
期刊:
2010 10th IEEE International Conference on Computer and Information Technology
影响因子:
--
通讯作者:
N. Takahashi
N. Takahashi
中科院分区:
--
文献类型:
--
作者:
Subana Thanasegaran;Y. Tateiwa;Y. Katayama;N. Takahashi

文献摘要

被引文献

相似文献

防火墙是保护网络免受未经授权访问和安全威胁的部署最多的机制之一。然而,对于动态的网络环境,防火墙策略的维护是一项容易出错且复杂的任务。冲突是一种错误配置,当一个数据包与两个或多个过滤器匹配时,会导致过滤器的遮蔽和冗余。网络管理员重新配置筛选器以最大限度地减少冲突的影响,因为筛选器不会反映其预期效果。如今,思科防火墙和Linux iptabes中都使用基于时间的过滤器来及时控制网络流量。当数据包与同一时间内活动的两个或多个基于时间的过滤器匹配时,就会发生冲突。基于时间的过滤器中的冲突检测是必要的,因为现有的冲突检测技术变得无效,因为没有考虑对过滤器的及时分析。这个问题无论其重要性如何,在研究中都没有得到解决。为了解决这一问题,本文提出了一种n+1维的冲突检测方法(n表示包头中关键字段的个数),通过同时分析时间和空间来检测冲突。我们计算特征向量来检测冲突的过滤器,在计算的初始阶段丢弃非冲突的过滤器,并去除不必要的步骤。此外,我们实现了一个原型系统,并在考虑和不考虑时间的情况下对基于时间的过滤器进行了实验。我们发现,当考虑时间时,大约50%的冲突过滤器变得不冲突。因此,我们的基于时间的过滤器的冲突检测系统减少了管理员的工作量,因为用于重新配置的过滤器大大减少。
Firewalls are one of the most deployed mechanisms to protect the network from unauthorized access and security threats. However, maintenance of firewall policy is an error-prone and complicated task for a dynamic network environment. Conflict is a misconfiguration that happens when a packet matches two or more filters resulting in shadowing and redundancy of the filters. Network administrators reconfigure the filters to minimize the effect of conflicts, as the filters do not reflect for what it was intended. Nowadays, time-based filters are used in CISCO firewalls and LINUX Iptables to control network traffic in time. Conflict occurs when a packet matches two or more time-based filters active in the same timing. Detection of conflicts in time-based filters is necessary, because the existing conflict detection techniques turns ineffective, as analysis of filters in time is not considered. This problem is not been addressed in research regardless of its significance. To resolve it, in this paper, we propose an n+1 dimensional approach (n refers the number of key fields in a packet header) to detect conflicts by analyzing time and space simultaneously. We compute characterization vectors to detect the conflicting filters which discards the non-conflicting filters in the initial stage of computation and remove the unnecessary steps. Further, we implemented a prototype system and conducted experiments on time-based filters with and without considering time. We found that approximately 50% of conflicting filters becomes non-conflicting when time is considered. Hence, our conflict detection system for time-based filters reduces the workload of the administrator as the filters for reconfiguration is considerably reduced.