DocumentCode :
2207279
Title :
Simultaneous Analysis of Time and Space for Conflict Detection in Time-Based Firewall Policies
Author :
Thanasegaran, Subana ; Tateiwa, Yuichiro ; Katayama, Yoshiaki ; Takahashi, Naohisa
Author_Institution :
Dept. of Comput. Sci. & Eng., Nagoya Inst. of Technol., Nagoya, Japan
fYear :
2010
fDate :
June 29 2010-July 1 2010
Firstpage :
1015
Lastpage :
1021
Abstract :
Firewalls are one of the most deployed mechanisms to protect the network from unauthorized access and security threats. However, maintenance of firewall policy is an error-prone and complicated task for a dynamic network environment. Conflict is a misconfiguration that happens when a packet matches two or more filters resulting in shadowing and redundancy of the filters. Network administrators reconfigure the filters to minimize the effect of conflicts, as the filters do not reflect for what it was intended. Nowadays, time-based filters are used in CISCO firewalls and LINUX Iptables to control network traffic in time. Conflict occurs when a packet matches two or more time-based filters active in the same timing. Detection of conflicts in time-based filters is necessary, because the existing conflict detection techniques turns ineffective, as analysis of filters in time is not considered. This problem is not been addressed in research regardless of its significance. To resolve it, in this paper, we propose an n+1 dimensional approach (n refers the number of key fields in a packet header) to detect conflicts by analyzing time and space simultaneously. We compute characterization vectors to detect the conflicting filters which discards the non-conflicting filters in the initial stage of computation and remove the unnecessary steps. Further, we implemented a prototype system and conducted experiments on time-based filters with and without considering time. We found that approximately 50% of conflicting filters becomes non-conflicting when time is considered. Hence, our conflict detection system for time-based filters reduces the workload of the administrator as the filters for reconfiguration is considerably reduced.
Keywords :
Linux; authorisation; computer network security; CISCO firewalls; conflict detection; dynamic network environment; network administrators; packet matches; simultaneous analysis; time based firewall policies; Active filters; Fires; IP networks; Information filters; Matched filters; Topology; Packet filtering; firewall mis-configuration; time-based rules;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location :
Bradford
Print_ISBN :
978-1-4244-7547-6
Type :
conf
DOI :
10.1109/CIT.2010.186
Filename :
5578622
Link To Document :
بازگشت