Dissertation > Excellent graduate degree dissertation topics show

Research on Optimization to Firewall Based on Statistical Analysis

Author: ZhangLi
Tutor: FuHeGang
School: Chongqing University
Course: Computer Software and Theory
Keywords: statistic analysis reorder rule set default rules conflict detection firewall
CLC: TP393.08
Type: Master's thesis
Year: 2011
Downloads: 35
Quote: 0
Read: Download Dissertation

Abstract


With the development of internet, more and more companies began to expand their business through the internet, which brings up more and more network security problems. As a result, various network security products have being born. Firewall, as the earliest and the widest used security product, plays a key role in protecting networks. For the special position of firewall in networks, the correctness of the rule set affects the efficiency of the firewall, and then affects the whole network. Because of this, more and more attention is being paid to firewall researches.Generally, firewall rules are predetermined and have the strict priority restrictions. When the network flow characteristics changed, these rules may limit the performance of firewall. In order to improve the adaptive optimization ability of firewall, some experts and scholars propose a kind of firewall based on statistics analysis. This kind of firewall will dynamically reorder filtering rules according to the network flow characteristics, aimed at making the rules which have matched more packets in the past time own higher priority.The adjustment of rules order without any constraints will change the firewall security policy. On this paper, firstly we define various conflicts between rules and then design a kind of conflict detection algorithm. Consequently, we propose an algorithm which dynamically reorders filtering rules without breaking the firewall security policy.During the adjustment of rule set, previous algorithms ignored the packets matched with default rules. The special position of default rules in rule set makes it needs the most times of comparison when matching a packet. This paper proposes a firewall-optimization method based on default-rules. This method begins by the matching probability of firewall rules, extracting some simple rules from the default-rules based on the firewall logs. After analyzing the relationship between the simple rules and the existing rules, emerge these simple rules into the new rules. Then evaluate the impacts these new rules made on the firewall and add some of the new rules to the rules library selectively, to implement the optimization for the linear match of the firewall.The experiments of this paper contain two parts, one implements the method of reordering rules, the other implements the method of firewall-optimization based on default-rules. Through the results of two experiments, we can conclude that, generally, the two methods can reduce the average number of rules matches, elevating the performance of firewall.At the end of this paper, we analyzed and summarized the research achievement as well as the existing problems of this paper, which defines the further research directions for the author.

Related Dissertations

  1. Research of Campus Network Security System,TP393.08
  2. The Research of Implementation on DDOS Attacking Simulation and Defence in the Military Network,TP393.08
  3. Design and Implementation of Packet Filter Rule Framework of Firewall,TP393.08
  4. Snort intrusion detection system based on improved system design and implementation,TP393.08
  5. Ship mountain of e-government network security solutions outside the network design and implementation,TP393.08
  6. Huzhou City Police network firewalls and Intrusion Detection System Design and Implementation,TP393.08
  7. Study and Application on Firewall System of Jiangxi Province Local Taxation Bureau,TP393.08
  8. Design and Implementation of Assistant Management System Server Based on Hardware Firewall,TP393.08
  9. Firewall and three switch - based campus network security policy research,TP393.08
  10. Gansu Fuyuan Chemical analysis and design of integrated office platform,TP311.52
  11. The Design and Implementation of A Military University Network in Security and Reliability,TP393.18
  12. Research and Implementation of Database Firewall Based on Netfilter,TP393.08
  13. The Research of IPSec Tunneling Based on Routing Switch Technology,TP393.08
  14. Fast protocol identification based firewall system design and implementation,TP393.08
  15. Firewall policy conflict detection and visualization,TP393.08
  16. Research on Trojan Horse Transmis Sion Technology Based on HTTPS and WEB SERVICE Shanghai Jiao Tong University,TP393.08
  17. Research and Implementation of High Performance Rule Matching Key Technology for IPv6 Firewall,TP393.08
  18. Research of Key Technology of Firewall Security Policy Configuration,TP393.08
  19. Research and Implement on Home Gateway Based on Embedded Linux,TP368.1
  20. Semantic Conflict Detection and Its Implementation Based on Implication Reasoning,TP391.1
  21. Research of Collaboration Design Base on Animation Model,TB472

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile