DocumentCode :
145364
Title :
Automatic Verification of Security Policies in Firewalls with Dynamic Rule Sequence
Author :
Gawanmeh, Amjad
Author_Institution :
Dept. of Electr. & Comput. Eng., Khalifa Univ. of Sci., Technol. & Res., Sharjah, United Arab Emirates
fYear :
2014
fDate :
7-9 April 2014
Firstpage :
279
Lastpage :
284
Abstract :
Security policies play an important role in the security of communication networks. They are normally defined at a high level of abstraction and implemented in firewalls, which are the first defense to secure networks against attacks and unauthorized access. When security policies are implemented in firewalls, anomalities and conflicts that may arise from different policies should be taken into consideration. On the other hand, Firewalls conduct random sequence order shuffling during their operation to prevent certain security attacks. This may result in an incorrect implementation of high level policies that depend on the order of rules inspection in the firewall. This paper presents a formal model of firewall rules sequence and a novel method that verifies the set of security policies when rules sequence changes. The method is tested on synthetic firewall of practical size, where the obtained results demonstrate the ability of firewalls to maintain the functional behavior of security policies during their runtime operation. The detailed analysis shows that the proposed method can be applied on firewalls with dynamic rule sequence in real time.
Keywords :
authorisation; firewalls; formal verification; anomality; automatic security policy verification; communication network security; conflict; dynamic rule sequence; firewall rule sequence; firewalls; formal model; network defense; random sequence order shuffling; rule inspection; runtime operation; security attack; unauthorized access; Abstracts; Engines; IP networks; Inspection; Ports (Computers); Dynamic Rule Sequence; Firewall Security Policy; Firewall Verification; Formal Model; Rules Sequence Order;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Technology: New Generations (ITNG), 2014 11th International Conference on
Conference_Location :
Las Vegas, NV
Print_ISBN :
978-1-4799-3187-3
Type :
conf
DOI :
10.1109/ITNG.2014.29
Filename :
6822211
Link To Document :
بازگشت