首页 | 本学科首页   官方微博 | 高级检索  
     

一种基于冲突检测的无关联规则集匹配算法
引用本文:施荣华,莫锐,赵文涛. 一种基于冲突检测的无关联规则集匹配算法[J]. 计算机工程与科学, 2010, 32(10): 1-4. DOI: 10.3969/j.issn.1007130X.2010.
作者姓名:施荣华  莫锐  赵文涛
作者单位:1. 中南大学信息科学与工程学院,湖南,长沙,410083
2. 国防科学技术大学计算机学院,湖南,长沙,410073
摘    要:防火墙已经成为网络安全体系中一个关键的角色,对防火墙的管理越来越受到重视。本文针对在防火墙管理中容易出现的过滤规则冲突问题和规则匹配效率问题,提出了一种基于冲突检测的无关联规则集匹配算法。本文通过对规则进行分析,确定了规则库中的规则应该符合的五个关系;通过对冲突规则的分类,得到了按照各种冲突的特性进行冲突检测产生的状态图,有助于对防火墙的现有规则库进行重写优化。本文在分析传统的线性顺序规则匹配算法和树形规则匹配算法的基础上,提出一种基于冲突检测的无关联规则集匹配算法,其平均比较次数为O(lg(n)),性能上大大优于现有的算法。

关 键 词:防火墙  规则集  冲突检测  无关联
收稿时间:2009-07-16
修稿时间:2009-12-03

An Irrelative Rule Set Match Algorithm Based on Collision Detection
SHI Rong-hua,MO Rui,ZHAO Wen-tao. An Irrelative Rule Set Match Algorithm Based on Collision Detection[J]. Computer Engineering & Science, 2010, 32(10): 1-4. DOI: 10.3969/j.issn.1007130X.2010.
Authors:SHI Rong-hua  MO Rui  ZHAO Wen-tao
Affiliation:SHI Rong-hua1,MO Rui1,ZHAO Wen-tao2(1.School of Information Science and Engineering,Central South University,Changsha 410083,2.School of Computer Science,National University of Defense Technology,Changsha 410073,China)
Abstract:The fire wall has already become a key role in the network security architecture,and more and more attention has been paid to the management of firewalls. This paper aims at the problems of rule collision and rule match efficiency in the management of firewalls,and submits an irrelevant rule set match algorithm based on  collision detection. By analyzing  the filtering rules,the paper confirms 5 relations that the rules should be matched;by categorizing  the collision rules,the paper concludes the collision detection state diagram according to the collision's characteristics,which helps to optimize the firewall rule set. Based on the analysis of the traditional liner match algorithm and the tree match algorithm,the paper submits an irrelative rule set match algorithm based on collision detection.The efficiency of the algorithm is O(log(n)) on the average and the performance of the algorithm is better than the traditional ones.
Keywords:firewall  rule set  collision detection  irrelative
本文献已被 CNKI 万方数据 等数据库收录!
点击此处可从《计算机工程与科学》浏览原始摘要信息
点击此处可从《计算机工程与科学》下载免费的PDF全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号