p.1899
p.1903
p.1911
p.1920
p.1925
p.1931
p.1935
p.1940
p.1944
An Improved Method of Firewall Policy Anomaly Detection Based on Decision Tree
Abstract:
Anomalous access control policy on firewall reduces the efficiency of the equipment, thus affecting the overall security of the network. This paper introduces an improved method of firewall policy anomaly detection based on decision tree, by transforming all the firewall access control rules into a decision tree to store the information in a tree data structure, each rule corresponds to the only one path of the tree. The experiment results show that this method solves some shortcomings in the existing decision tree based firewall policy anomaly detection methods, avoids spending time on comparison of rules whose attribute domains are uncorrelated and traversal comparison of all rules, reduces its running time and improves the efficiency of anomaly detection.
Info:
Periodical:
Pages:
1925-1930
Citation:
Online since:
October 2014
Authors:
Keywords:
Price:
Сopyright:
© 2014 Trans Tech Publications Ltd. All Rights Reserved
Share:
Citation: