講演抄録/キーワード |
講演名 |
2009-01-29 15:20
ファイアウォールポリシの設定誤りの解析のためのビットベクタ型空間計算法 ○タナセガラン スバナ・殷 奕・立岩佑一郎・片山善章・高橋直久(名工大) IA2008-65 |
抄録 |
(和) |
Packet filtering in firewalls operates at the network level of the OSI model, or the IP layer of TCP/IP. In a packet filtering each packet is compared to a set of conditions before it is forwarded. Depending on the header of the packet, the firewall accepts or denies the packet. Since business needs are dynamic, firewall policies are constantly being changed and modified. Firewall administration teams in large organizations often process dozens of filter additions and changes daily. This continuous flux causes the firewall configuration to grow dramatically over time. A huge and, subsequently complex, firewall configuration is hard to manage and may require lengthy research in order to add or change a filter and results in mis-configurations in firewall policies. Powerful error classification method was proposed based upon the geometrical interpretation of policies in order to detect such mis-configurations in firewall policies. However, as the filters and key fields of the header increase, it demands high memory and computation time. We propose a topological approach called BISCAL (Bit-vector based spatial calculus) to detect the conflicts in the firewall policies to solve this problem. |
(英) |
Packet filtering in firewalls operates at the network level of the OSI model, or the IP layer of TCP/IP. In a packet filtering each packet is compared to a set of conditions before it is forwarded. Depending on the header of the packet, the firewall accepts or denies the packet. Since business needs are dynamic, firewall policies are constantly being changed and modified. Firewall administration teams in large organizations often process dozens of filter additions and changes daily. This continuous flux causes the firewall configuration to grow dramatically over time. A huge and, subsequently complex, firewall configuration is hard to manage and may require lengthy research in order to add or change a filter and results in mis-configurations in firewall policies. Powerful error classification method was proposed based upon the geometrical interpretation of policies in order to detect such mis-configurations in firewall policies. However, as the filters and key fields of the header increase, it demands high memory and computation time. We propose a topological approach called BISCAL (Bit-vector based spatial calculus) to detect the conflicts in the firewall policies to solve this problem. |
キーワード |
(和) |
パケット フィルター / ネットワーク セキュリティー / ファイアウォール / ファイアウォール ポリシ / コンフリクト 検出 / / / |
(英) |
packet filters / network security / firewall / firewall policy / conflict detection / / / |
文献情報 |
信学技報, vol. 108, no. 409, IA2008-65, pp. 101-106, 2009年1月. |
資料番号 |
IA2008-65 |
発行日 |
2009-01-21 (IA) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
著作権に ついて |
技術研究報告に掲載された論文の著作権は電子情報通信学会に帰属します.(許諾番号:10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
PDFダウンロード |
IA2008-65 |