Firewall
InterviewTime limit1sMemory limit1024 MB
Simulate a rule list where each packet is checked top to bottom against port, IP, and a rate limit over the last 1000 packets, printing the action for every matching rule until accept or drop.
- Level
Medium5 of 10
- Topics
- Simulation, Implementation, Queue, Array
- Solved
- No attempts yet
Problem
On the Internet, there are many bad guys who always try to hack other people's computers. They steal cat pictures, bank logins and membership lists on programming dating sites. One of the first countermeasures against network-based attacks is the firewall. A firewall filters some network traffic based on different criteria, to shut out unauthorized access. In this problem, we are going to code the part of the firewall that determines whether a certain message sent to a server over a network should be dropped or accepted.
A firewall consists of a number of rules in a long list. A rule is on the form "if [list of conditions] are true, perform an action". These conditions are one of
port=XYZ- if the message was sent to portXYZ.ip=XYZ- if the message was sent from the IP-addressXYZ.limit=XYZ- if at leastXYZof the last 1000 messages (including the one just received) was sent from this IP-address.
and the actions are one of
accept- let the package through the firewall. Printaccept packet-ID.log- printlog packet-ID.drop- block the packet. Printdrop packet-ID.
Some examples of rules with explanations:
accept- always accept the packet.accept ip=127.0.0.1- accept the packet if it comes from the IP-address127.0.0.1.drop port=22 ip=192.168.1.1- drop the packet if its from the IP-address192.168.1.1and sent to port22.log port=80 limit=500- log the packet if it was sent to port80, and at least half of the last 1000 messenges was sent from this IP-address.
When a packet enters the firewall, it looks at every rule in the list, top to bottom, until it reaches a rule that matches the packet. The given firewall will always be constructed such that a packet will be accepted or dropped before the end of the list.
Input
The first line of input contains an integer , the number of rules in the firewall.
The next lines contains the rules in the list, one rule on each line.
The next row contains an integer , the number of packets arriving to the firewall. They are given in the order of arrival. A packet is on the form IP:port, for example 127.0.0.1:123. The packet ID is just the position of the packet in this list. The first packet has id and the last ID .
A port is an integer .
Output
For each packet, you are to run it through the firewall until it is accepted or dropped. Each action that is taken describes what to print. Note that since the action log doesn't stop the packet in the firewall, each packet could result in multiple lines of output.