摘要:
A system, computer-implementable method, and computer-usable medium for resolving discrepancies between diverse firewall designs. In a preferred embodiment of the present invention, a firewall design manager receives at least two designs for a rule-based system and computing at least one functional discrepancy between the at least two designs utilizing decision diagrams.
摘要:
A system, method, and computer-usable medium for removing redundancy from packet classifiers. In a preferred embodiment of the present invention, a packet classifier is implemented as a sequence of rules. A redundancy manager marks at least one upward redundant rule and at least one downward redundant rule. The redundancy manager removes at least one rule marked as upward redundant and at least one rule marked as downward redundant.
摘要:
A system, method and computer-usable medium for designing a firewall to protect a data processing system. A user first specifies a firewall decision diagram. The firewall decision diagram is then reduced and marked. Finally, a firewall is generated from the marked firewall decision diagram.