Journal of System Simulation ›› 2015, Vol. 27 ›› Issue (11): 2770-2777.

Previous Articles     Next Articles

Policies Conflict Detection Algorithm Coordinated Defense-oriented of Firewall and IDS/IPS

Qiu Song1, Jiao Jian2, Zhang Dongyang3   

  1. 1. Department of Engineering, Xiangyuan Hexin Power Co. Ltd. , Taiyuan 030001, China;
    2. Department of Computer, Beijing Information Science & Technology University. Beijing 100192, China;
    3. Department of Computer, North China Electric Power University, Baoding 071002, China
  • Received:2014-04-19 Revised:2014-07-27 Online:2015-11-08 Published:2020-08-05

Abstract: Coping with the distributed and complex threaten of networking attack, the requirement of coordinated defense of Firewall and IDS/IPS are becoming more and more urgent. As the existence of uncertainty of the judgment of Intrusion performed by IDS/IPS, Firewall and IDS/IPS often perform contradict action, that the same package matched the both rules of Firewall and IDS/IPS, and conflict arose, which would lead to illegal access control or deny of legal access control. The policies conflict detection algorithm of coordinated defense of Firewall and IDS/IPS were researched. The semantic models of firewall policy and IDS/IPS policy were proposed, the classification of the policies conflicts was proposed, and the conflicts detection algorithm of policies were proposed using OBDD (ordered binary decision diagram). The experiment demonstrates the correctness and scalability of the algorithm, and the proportion of the conflicts in real network scenario.

Key words: firewall, coordinated defense, conflict detection, ordered binary decision diagram

CLC Number: