• DocumentCode
    2235482
  • Title

    Inconsistency Detection System for Security Policy and Firewall Policy

  • Author

    Yin, Yi ; Xu, Xiaodong ; Katayama, Yoshiaki ; Takahashi, Naohisa

  • Author_Institution
    Sch. of Comput. Sci. & Technol., Nanjing Normal Univ., Nanjing, China
  • fYear
    2010
  • fDate
    17-19 Nov. 2010
  • Firstpage
    294
  • Lastpage
    297
  • Abstract
    Packet filtering in firewall either accepts or denies network packets based upon a set of pre-defined filters called firewall policy. Firewall policy is designed under the instruction of security policy. A network security policy is a generic document that outlines the needs for computer network access permissions. And it determines how firewall filters are designed. If inconsistencies, such as redundant filters, insufficient filters or contradict filters, exist between security policy and firewall policy, firewall policy could not filter packets exactly, and the network protected by the firewall will be affected. To resolve this problem, we propose an inconsistency detection system to detect the inconsistencies between the security policy and firewall policy. When the administrator could not get host IP addresses, port number and other specific values, according to the network configurations, our proposed system could transform the network security policy and firewall policy to the same range value, represent and analyze their spatial relationships to detect their inconsistencies. The proposed system has been successfully implemented in a prototype system. We have been confirmed the effectiveness of the proposed system.
  • Keywords
    IP networks; authorisation; computer network security; IP address; computer network access permission; firewall policy; generic document; inconsistency detection system; network configuration; network packet; network security policy; packet filtering; port number; predefined filter; firewall; inconsistency detection; security policy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networking and Computing (ICNC), 2010 First International Conference on
  • Conference_Location
    Higashi-Hiroshima
  • Print_ISBN
    978-1-4244-8918-3
  • Electronic_ISBN
    978-0-7695-4277-5
  • Type

    conf

  • DOI
    10.1109/IC-NC.2010.45
  • Filename
    5695255