Firewall Policy Advisor for anomaly discovery and rule editing
- 15 October 2003
- proceedings article
- Published by Institute of Electrical and Electronics Engineers (IEEE)
Abstract
Firewalls are core elements in network security. However, managing firewall rules, es- pecially for enterprize networks, has become complex and error-prone. Firewall filtering rules have to be carefully written and organized in order to correctly implement the secu- rity policy. In addition, inserting or modifying a filtering rule requires thorough analysis of the relationship between this rule and other rules in order to determine the proper order of this rule and commit the updates. In this paper, we present a set of techniques and al- gorithms that provide (1) automatic discovery of firewall policy anomalies to reveal rule conflicts and potential problems in legacy firewalls, and (2) anomaly-free policy editing for rule insertion, removal and modification. This is implemented in a user-friendly tool called "Firewall Policy Advisor." The Firewall Policy Advisor significantly simplifies the management of any generic firewall policy written as filtering rules, while minimizing network vulnerability due to firewall rule misconfiguration.Keywords
This publication has 9 references indexed in Scilit:
- Firmato: a novel firewall management toolkitPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Policy-based management: bridging the gapPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2003
- Filtering postures: local enforcement for global policiesPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Detecting and resolving packet filter conflictsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Fang: a firewall analysis enginePublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- A modular approach to packet classification: algorithms and resultsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- Fast firewall implementations for software-based and hardware-based routersPublished by Association for Computing Machinery (ACM) ,2001
- Packet classification using tuple space searchACM SIGCOMM Computer Communication Review, 1999
- Conflict Analysis for Management PoliciesPublished by Springer Nature ,1997