DocumentCode
2235482
Title
Inconsistency Detection System for Security Policy and Firewall Policy
Author
Yin, Yi ; Xu, Xiaodong ; Katayama, Yoshiaki ; Takahashi, Naohisa
Author_Institution
Sch. of Comput. Sci. & Technol., Nanjing Normal Univ., Nanjing, China
fYear
2010
fDate
17-19 Nov. 2010
Firstpage
294
Lastpage
297
Abstract
Packet filtering in firewall either accepts or denies network packets based upon a set of pre-defined filters called firewall policy. Firewall policy is designed under the instruction of security policy. A network security policy is a generic document that outlines the needs for computer network access permissions. And it determines how firewall filters are designed. If inconsistencies, such as redundant filters, insufficient filters or contradict filters, exist between security policy and firewall policy, firewall policy could not filter packets exactly, and the network protected by the firewall will be affected. To resolve this problem, we propose an inconsistency detection system to detect the inconsistencies between the security policy and firewall policy. When the administrator could not get host IP addresses, port number and other specific values, according to the network configurations, our proposed system could transform the network security policy and firewall policy to the same range value, represent and analyze their spatial relationships to detect their inconsistencies. The proposed system has been successfully implemented in a prototype system. We have been confirmed the effectiveness of the proposed system.
Keywords
IP networks; authorisation; computer network security; IP address; computer network access permission; firewall policy; generic document; inconsistency detection system; network configuration; network packet; network security policy; packet filtering; port number; predefined filter; firewall; inconsistency detection; security policy;
fLanguage
English
Publisher
ieee
Conference_Titel
Networking and Computing (ICNC), 2010 First International Conference on
Conference_Location
Higashi-Hiroshima
Print_ISBN
978-1-4244-8918-3
Electronic_ISBN
978-0-7695-4277-5
Type
conf
DOI
10.1109/IC-NC.2010.45
Filename
5695255
Link To Document