• DocumentCode
    2828791
  • Title

    Firmato: a novel firewall management toolkit

  • Author

    Bartal, Yair ; Mayer, Alain ; Nissim, Kobbi ; Wool, Avishai

  • Author_Institution
    Lucent Technol., AT&T Bell Labs., Murray Hill, NJ, USA
  • fYear
    1999
  • fDate
    1999
  • Firstpage
    17
  • Lastpage
    31
  • Abstract
    In recent years, packet filtering firewalls have seen some impressive technological advances (e.g., stateful inspection, transparency, performance, etc.) and widespread deployment. In contrast, firewall and security management technology is lacking. We present Firmato, a firewall management toolkit, with the following distinguishing properties and components: (1) an entity relationship model containing, in a unified form, global knowledge of the security policy and of the network topology; (2) a model definition language, which we use as an interface to define an instance of the entity relationship model; (3) a model compiler translating the global knowledge of the model into firewall-specific configuration files; and (4) a graphical firewall rule illustrator. We demonstrate Firmato´s capabilities on a realistic example, thus showing that firewall management can be done successfully at an appropriate level of abstraction. We implemented our toolkit to work with a commercially available firewall product. We believe that our approach is an important step towards streamlining the process of configuring and managing firewalls, especially in complex, multi firewall installations
  • Keywords
    computer network management; entity-relationship modelling; program compilers; security of data; user interfaces; Firmato; abstraction; commercially available firewall product; entity relationship model; firewall management toolkit; firewall-specific configuration files; global knowledge; graphical firewall rule illustrator; interface; model compiler; model definition language; multi firewall installations; network topology; packet filtering firewalls; security management technology; security policy; stateful inspection; Books; Finite impulse response filter; Fires; Hip; Home appliances; Inspection; Internet; Security; Topology; Wool;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 1999. Proceedings of the 1999 IEEE Symposium on
  • Conference_Location
    Oakland, CA
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-0176-1
  • Type

    conf

  • DOI
    10.1109/SECPRI.1999.766714
  • Filename
    766714