作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (2): 124-126. doi: 10.3969/j.issn.1000-3428.2008.02.041

• 安全技术 • 上一篇    下一篇

过量规则下网络访问控制方法

王一飞1,程 彤1,冯宇平2   

  1. (1. 中国人寿保险股份有限公司信息技术部,北京 100020;2. 北京方正奥德计算机系统有限公司,北京 100871)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-01-20 发布日期:2008-01-20

Network Access Control Method with Excessive Filtering Rules

WANG Yi-fei1, CHENG Tong1, FENG Yu-ping2   

  1. (1. Department of Information Technology, China Life Insurance Company Ltd., Beijing 100020;2. Beijing Founder Order Computer System Company Ltd., Beijing 100871)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-01-20 Published:2008-01-20

摘要:

分析过量规则对网络访问控制设备性能的影响,讨论针对这一问题的解决方法。基于优化规则、多设备分担负载的思想,提出IP编组与访问控制分离、管理与优化分离的串接-两分离访问控制法,设计了相应的双防火墙串接设备部署方案和超越应用的规则编组优化方案。物理仿真实验验证了串接-两分离访问控制法的可行性与优越性。

关键词: 网络访问控制, 过量规则, 串接-两分离访问控制法, 规则编组优化

Abstract: After analyzing the excessive filtering rules, a solution to increase the performance of network access control equipment is proposed. Based on ideas of optimizing rules and load balance of multi-equipment, the approach of Serial Double-separation Access Control(SDAC) method is put forward. In this method, organizing source IP into groups (control of source address) is separated from opening access port (control of service), and the management of firewall is separated from the optimization of access control. Double firewall serial setting scheme for the first separation and optimizing rules scheme for the second separation are designed. Feasibility and superiority of SDAC are proved by physical simulation experiments.

Key words: network access control, excessive filtering rules, Serial Double-separation Access Control(SDAC) method, optimizing rules

中图分类号: