Middlebox穿越的安全成本

发布于 2025-01-07 22:29:27 字数 199 浏览 0 评论 0原文

我想计算虚拟机从一台物理服务器迁移到另一台物理服务器时中间盒遍历的安全成本。中间的盒子可以是防火墙或 IPS/IDS,其中包含检查穿过它们的虚拟机的规则。现在想象一个最简单的场景,唯一的问题是找到通过中间件规则检查VM的成本(这就是我所说的安全成本),并根据这个成本找到最佳路径。

然而,已经有一些协议,例如 BGP 或 OSPF,但不幸的是,它们都没有考虑安全成本。

I want to calculate the security cost of middlebox traversal when VM migrate from one physical server to another. Middle boxes can be firewalls or IPS/IDS containing rules checking the VM traversing them. Now imagine the most simple scenario that the only problem is to find the cost of checking VM by middlebox rules (this is what I call it security cost), and according to this cost finding the optimum path.

However there are already some protocols out there such as BGP or OSPF, but unfortunately non of them consider the security cost.

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

因为看清所以看轻 2025-01-14 22:29:27

我不同意到达最佳路径的正确方法是计算防火墙规则。相反,我会关注大量规则的影响。您不应尝试找出存在多少规则或启用了哪些安全功能,而应将最佳路径定义为网络延迟最低的路径。这可能很容易测量。如果有一个包含很多规则的防火墙并且仍然可以以更快的速度处理流量,那么您不应该介意通过该防火墙,对吗?

I do not agree that the right way to arrive at the optimum path is to calculate firewall rules. Instead, I would focus on the impact of large set of rules. Instead of trying to find out how many rules are present or what security features are enabled, you should define the optimum path as the one that has lowest network latency. That is probably easily measured. If there is a firewall with lot of rules and can still process traffic at faster rate, you should not mind going through that firewall, right?

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文