Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2007, Vol. 33 ›› Issue (11): 132-134. doi: 10.3969/j.issn.1000-3428.2007.11.049

• Security Technology • Previous Articles     Next Articles

Algorithm for Fast Detecting Firewall Rule Configuration Mistakes

WANG Weiping, CHEN Wenhui, ZHU Weiwei, CHEN Huaping   

  1. (Dept. of Information Management & Decision Science, University of Science & Technology of China, Hefei 230026)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-06-05 Published:2007-06-05

防火墙规则配置错误快速检测算法

王卫平,陈文惠,朱卫未,陈华平   

  1. (中国科学技术大学信息管理与决策科学系,合肥 230026)

Abstract: As enterprises’ network security barrier, firewalls play a very important role. Since enterprises configurate firewalls according to its need; the rule table will be included. However, problems may occur during configuration. On one hand, the administrator himself may make some mistakes during initial configuration. On the other hand, possibility of conflicts among different rules increases with rule numbers in the table growing. This paper analyzes possible mistakes in the configuration process. It introduces several familiar types of mistakes in configuration, puts forward the algorithm which can find mistakes. The paper improves the algorithm according to the characteristics of the firewall rule table, which increases efficiency of detecting configuration mistakes.

Key words: Firewall, Packet filtering, Rule conflict

摘要: 在防火墙的规则配置中潜伏着一些问题:安全管理员可能在最初配置规则表的时候,出现一些错误;随着规则表中规则数目的增长,不同的规则之间发生冲突的可能性也相应增加。该文对防火墙规则配置过程中可能出现的错误进行了分析,介绍了防火墙规则配置错误的几种常见类型,给出了发现错误的算法,并根据防火墙规则表的特点对算法进行了改进,提高了规则配置错误的检测效率。

关键词: 防火墙, 包过滤, 规则冲突

CLC Number: