返回
摘要
En 中文
Firewalls are the mainstay of enterprise security and the most widely adopted technology for protecting private networks. An error in a firewall policy either creates security holes that will allow malicious traffic to sneak into a private network or blocks legitimate traffic and disrupts normal business processes, which, in turn, could lead to irreparable, if not tragic, consequences. It has been observed that most firewall policies on the Internet are poorly designed and have many errors. Therefore, how one can design firewall policies correctly is an important issue. In this paper, we propose the method of diverse firewall design, which consists of three phases: a design phase, a comparison phase, and a resolution phase. In the design phase, the same requirement specification of a firewall policy is given to multiple teams who proceed independently to design different versions of the firewall policy. In the comparison phase, the resulting multiple versions are compared with each other to detect all functional discrepancies between them. In the resolution phase, all discrepancies are resolved, and a firewall that is agreed upon by all teams is generated. The major technical challenge in the method of diverse firewall design is how one can discover all functional discrepancies between two given firewall policies. We present a series of three efficient algorithms for solving this problem: a construction algorithm, a shaping algorithm, and a comparison algorithm. The algorithms for discovering all functional discrepancies between two given firewall policies can be used to perform firewall policy change impact analysis as well. Firewall policies often need to be changed, as networks evolve, and new threats emerge. Many firewall policy errors are caused by the unintended side effects of policy changes. Our algorithms can be used directly to compute the impact of firewall policy changes by computing the functional discrepancies between the policy before changes and the policy after changes.
Keyword:
firewall policy
policy design
design diversity
change impact analysis
network security
期刊
IF:
6
论文数:
5.2K
被引数:
1.1W
机构
引用论文
Solvent Effects in Organic Spectra: Dipole Forces and the Franck–Condon Principle有机光谱中的溶剂效应: 偶极力和franck-condon原理
A framework for understanding vulnerabilities in firewalls using a dataflow model of firewall internals
COMPUTERS & SECURITY
IF5.4

