Journal of Beijing University of Posts and Telecommunications

  • EI核心期刊

JOURNAL OF BEIJING UNIVERSITY OF POSTS AND TELECOM ›› 2006, Vol. 29 ›› Issue (5): 111-114.doi: 10.13190/jbupt.200605.111.lil

• Reports • Previous Articles     Next Articles

A Detection Algorithm for Rule Set Conflicts Based on Tuple Space Search

LI Lin, LU Xian-liang   

  1. Department of Computer Science, university of electronic science and technology, Chengdu 610054, China
  • Received:2005-10-08 Revised:1900-01-01 Online:2006-10-30 Published:2006-10-30
  • Contact: LI Lin

Abstract:

Adding a new firewall rule often conflicts with the existed ones, which leads to security vulnerabilities. In order to avoid such vulnerabilities, firewall administrators have to determine an appropriate position in the firewall rule set to be inserted, and identify all the rules conflicting with the new rule in advance. The time complexity of the current conflicts detection algorithm for firewall rule set is O(dN), which makes its performance very poor. A new algorithm for detecting firewall rule set conflicts based on tuple space search is presented not only to find all the rules conflicting with the new rule, but also reduce the time complexity as O(logN+N/w). So it can efficiently help administrators determine an appropriate insertion position of the new rule to avoid vulnerabilities.

Key words: rule conflicts, tuple space search, security holes

CLC Number: