首页> 外文会议>International Conference on Soft Computing and Pattern Recognition >A Novel Concept of Firewall-Filtering Service Based on Rules Trust-Risk Assessment
【24h】

A Novel Concept of Firewall-Filtering Service Based on Rules Trust-Risk Assessment

机译:基于规则信任风险评估的防火墙过滤服务的新颖概念

获取原文

摘要

The importance given to firewalls as a security mechanism for protecting sensitive and private infrastructures has been well justified in literature. Nowadays, we consider firewalls as one of the most important security mechanisms that is widely deployed and highly approved. The main goal of this fundamental security component is to provide a filtering service by blocking or providing access to specific areas and segments of a network based on a set of filtering rules defined with regards to the global security policy. Hence, the effectiveness of the protection provided by a firewall is governed by the efficiency of the filtering policy deployed in that firewall. To enhance the quality of the filtering service provided by firewalls, we propose a novel filtering technique that integrates a risk assessment approach to evaluate the risk associated to firewalls rules. Our goal is to strengthen the filtering service with pertinent information relative to rules risk values that allows (i) changing the actions associated to critical rules in specific/critical contexts or (ii) dynamically injecting new rules in the firewall that refine other rules (by giving precision or reducing domains) to reduce the risk or (iii) changing the behavior of the firewall by changing its configuration (the set of rules) to avoid malicious scenarios.
机译:给防火墙作为安全机制保护敏感和私人基础设施的重要性在文献中得到了很好的理由。目前,我们认为防火墙作为被广泛部署和高度认可的最重要的安全机制之一。这个基本的安全组件的主要目标是通过阻断或提供访问特定的领域和基于一组过滤与关于全球安全策略中定义的规则的网络段提供过滤服务。因此,通过一个防火墙所提供的保护的有效性是由部署在防火墙过滤策略的效率支配。为了提高通过防火墙提供的过滤服务的质量,我们提出了一个新的过滤技术,集成了一个风险评估方法,以评估相关联的防火墙规则的风险。我们的目标是加强与相关规则的风险值的相关信息,让(我)改变关联到特定/关键上下文或关键规则的行为(二)防火墙动态地注入新的规则,细化其他规则(通过过滤服务给精度或降低结构域)来降低风险或(iii)通过改变其构型(该组规则),以避免恶意情景改变防火墙的行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号