科技报告详细信息
Enhancements to the Vantage Firewall Analyzer
Bhatt, Sandeep ; Rao, Prasad
HP Development Company
关键词: firewall;    rule set;    overlap;    analysis;    rectangle intersection;   
RP-ID  :  HPL-2007-154R1
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

The Vantage firewall analysis toolkit simplifies the complexity of managing firewall access control rule sets. Firewall rule sets typically become increasingly unwieldy over time. It is common for firewalls to have hundreds, or even thousands, of rules. As a result, administrators do not know how rules interact with each other. In a previous technical report [BHR], we presented our tool to analyze Checkpoint firewalls. Given two rule sets, the tool produces a comprehensive list of the traffic that one rule set will let through but not the other one. As such, we can use it to compare the existing rule set with a second rule set containing the proposed changes. The administrator can visually check if the difference in traffic patterns corresponds to what he or she intended in proposing the changes. This report presents improvements and extensions to the toolkit. In particular, we present faster underlying algorithms and improved software architecture. We also extend the toolkit to analyze HP_UX IPFilter rule sets. 19 PagesExternal Posting Date: June 7, 2008 [Fulltext].Approved for External PublicationInternal Posting Date: June 7, 2008 [Fulltext]

【 预 览 】
附件列表
Files Size Format View
RO201804100001736LZ 126KB PDF download
  文献评价指标  
  下载次数:19次 浏览次数:26次