首页 | 本学科首页   官方微博 | 高级检索  
     

面向大规模网络的基于政策的访问控制框架
引用本文:段海新,吴建平,李星. 面向大规模网络的基于政策的访问控制框架[J]. 软件学报, 2001, 12(12): 1739-1747
作者姓名:段海新  吴建平  李星
作者单位:清华大学信息网络工程研究中心,
基金项目:Supported by the National Grand Fundamental Research 973 Program of China under Grant No. G1999035810(国家重点基础研究发展规划973资助项目)
摘    要:研究防火墙(或过滤路由器)应用于传输网络中的管理问题与吞吐量问题.一方面,手工配置分布在各个接入点的大量防火墙,无法满足开放的、动态的网络环境的安全管理需求;另一方面,大量过滤规则的顺序查找导致了防火墙吞吐量下降.针对一个典型的传输网络和它的安全政策需求,提出了一种基于政策的访问控制框架(PACF),该框架基于3个层次的访问控制政策的抽象:组织访问控制政策(OACP)、全局访问控制政策(GACP)和本地访问控制政策(LACP).根据OACP,GACP从入侵监测系统和搜索引擎产生,作为LACP自动地、动态地分配到各防火墙中,由防火墙实施LACP.描述了GACP的分配算法和LACP的实施算法,提出了一种基于散列表的过滤规则查找算法.PACF能够大量减轻管理员的安全管理工作,在描述的安全政策需求下,基于散列表的规则查找算法能够将传统顺序查找算法的时间复杂度从O(N)降低到O(1),从而提高了防火墙的吞吐量.

关 键 词:计算机网络  网络安全  访问控制  防火墙  安全政策  散列表
文章编号:1000-9825/2001/12(12)1739-09
收稿时间:2000-04-28
修稿时间:2000-04-28

Policy-Based Access Control Framework for Large Networks
DUAN Hai-xin,WU Jian-ping and LI Xing. Policy-Based Access Control Framework for Large Networks[J]. Journal of Software, 2001, 12(12): 1739-1747
Authors:DUAN Hai-xin  WU Jian-ping  LI Xing
Abstract:Efforts of this paper focus on the issues about the management and throughput of firewalls (or screening routers) applied in transit networks. On the one hand, manual configuration of large amount of firewalls distributed in many access points cannot meet the requirements of security management in the open and dynamic environment. On the other hand, the ordinal lookup of filtering rules in firewall results in decrease of throughput. Aimed at a typical transit network and its security policy requirements, a policy-based access control framework (PACF) is proposed in this paper. This framework is based on three levels of abstract access control policy: organizational access control policy (OACP), global access control policy (GACP) and local access control policy (LACP). The GACP, which comes from the results of IDS and search engines according to OACP, is automatically and dynamically distributed to firewalls as LACPs. Each LACP is then enforced by an individual firewall. Some algorithms for distribution of GACP and enforcement of LACP are described. A hashbased algorithm is proposed for lookup of filtering rules in LACP. PACF largely reduces the management labor of the security administrator for large transit networks. Under the environment with policy requirements described in this paper, the new algorithm reduces the time complexity of lookup from O(N) of traditional sequential algorithm to O(1), which increases largely the throughput of firewalls.
Keywords:computer networks   network security   access control   firewall   security policy   hash table
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《软件学报》浏览原始摘要信息
点击此处可从《软件学报》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号