Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2010, Vol. 36 ›› Issue (22): 134-136. doi: 10.3969/j.issn.1000-3428.2010.22.047

• Networks and Communications • Previous Articles     Next Articles

Detection Algorithm for Firewall Policy Based on LE-Trie

LIANG Jian-wu, LONG Xiao-mei, LIU Jun-jun   

  1. (School of Information Science and Engineering, Central South University, Changsha 410075, China)
  • Online:2010-11-20 Published:2010-11-18

基于LE-Trie的防火墙策略检测算法

梁建武,龙晓梅,刘军军   

  1. (中南大学信息科学与工程学院,长沙 410075)
  • 作者简介:梁建武(1964-),男,高级工程师,主研方向:网络安全,冲突检测;龙晓梅、刘军军,硕士
  • 基金资助:
    国家自然科学基金资助项目(60173041)

Abstract: The firewall policy is a sequence of rules set, so it is very important to make the firewall work well and it must be without any conflicts. This paper introduces a description method based on LE-Trie data structure for firewall policy conflict detecting. Simulation result shows that using the LE-Trie storage rule table to describe the firewall policy can use less memory than the ordinary ones, and it can get a higher search speed as detecting conflicts.

Key words: network security, firewall policy, LE-Trie construction, rule conflicts

摘要: 防火墙策略是一系列具体的规则集合,策略的制定对防火墙功能的发挥至关重要,不能存在异常情况。为此,研究基于惰性展开的Trie数据结构,利用LE-Trie结构存储规则表,提出一种防火墙策略的冲突检测与消除算法。仿真结果表明,与使用普通Trie结构的算法相比,该算法具有更高的执行效率。

关键词: 网络安全, 防火墙策略, LE-Trie结构, 规则冲突

CLC Number: