|
 |
Bimonthly Since 1986 |
ISSN 1004-9037
|
|
 |
|
|
Publication Details |
Edited by: Editorial Board of Journal of Data Acquisition and Processing
P.O. Box 2704, Beijing 100190, P.R. China
Sponsored by: Institute of Computing Technology, CAS & China Computer Federation
Undertaken by: Institute of Computing Technology, CAS
Published by: SCIENCE PRESS, BEIJING, CHINA
Distributed by:
China: All Local Post Offices
|
|
|
|
|
|
|
|
|
|
|
09 May 2023, Volume 38 Issue 3
|
|
|
Abstract
Most private networks are secured by firewalls, which are crucial for safety. A firewall aims to inspect every inward and outgoing traffic before deciding whether to allow it. The rule-based firewall is a frequently used conventional firewall. However, conventional Listed-Rule firewalls have limits when it comes to task performance and is ineffective when used with some networks that have very large firewall rule sets. This paper suggests a model firewall design, "Tree-Rule Firewall," which has advantages and works with expansive networks like "cloud". This paper proposes a modified tree rule firewall (MTRFcloud) for removing redundant and shadowing rules, improving cloud network security. This work first generates a tree rule firewall for the corresponding firewall policy. The suggested modified tree rule firewall does not produce redundant rules and efficiently finds the shadow rules. Then, a modified Tree-Rule firewall that manages firewall rules was tested in a cloud setting. It is shown that the updated Tree-Rule firewall provides faster processing and greater network security. With a big network, like a cloud network, the modified Tree-Rule firewall is simpler to construct and efficiently removes the redundant and shadow rules.
Keyword
Firewall, Tree rules, cloud security, redundant rule, shadowing rule
PDF Download (click here)
|
|
|
|
|