论文标题
部分可观测时空混沌系统的无模型预测
Systematic review of automatic translation of high-level security policy into firewall rules
论文作者
论文摘要
防火墙是执行网络流量过滤的安全设备。它们在行业中无处不在,是一种用于执行组织安全政策的常见方法。安全策略是在高级抽象上指定的,其中诸如“仅在办公网络内的工作站上允许Web浏览”之类的语句,并且需要将其转换为低级防火墙规则以可执行。关于防火墙规则的优化,分析和平台独立性已经有很多工作,但是成功少得多的领域是将高级安全策略自动翻译成防火墙规则。除了提高规则的可读性外,这种翻译还可以使检测错误更容易。此纸张调查二十多篇论文,旨在根据在更高水平的抽象中指定的安全策略生成防火墙规则。它还概述了现代防火墙系统中的类似功能。大多数方法定义了专门的域语言,这些域语言被编译为防火墙规则集,其中一些依赖于正式规范,本体论或图形模型。随着时间的推移,方法的改善,但是在更广泛的应用之前,仍然需要解决许多缺点。
Firewalls are security devices that perform network traffic filtering. They are ubiquitous in the industry and are a common method used to enforce organizational security policy. Security policy is specified on a high level of abstraction, with statements such as "web browsing is allowed only on workstations inside the office network", and needs to be translated into low-level firewall rules to be enforceable. There has been a lot of work regarding optimization, analysis and platform independence of firewall rules, but an area that has seen much less success is automatic translation of high-level security policies into firewall rules. In addition to improving rules' readability, such translation would make it easier to detect errors.This paper surveys of over twenty papers that aim to generate firewall rules according to a security policy specified on a higher level of abstraction. It also presents an overview of similar features in modern firewall systems. Most approaches define specialized domain languages that get compiled into firewall rule sets, with some of them relying on formal specification, ontology, or graphical models. The approaches' have improved over time, but there are still many drawbacks that need to be solved before wider application.