• DocumentCode
    2843005
  • Title

    A declarative approach for global network security configuration verification and evaluation

  • Author

    Rahman, Mohammad Ashiqur ; Al-Shaer, Ehab

  • Author_Institution
    Dept. of Software & Inf. Syst., Univ. of North Carolina at Charlotte, Charlotte, NC, USA
  • fYear
    2011
  • fDate
    23-27 May 2011
  • Firstpage
    531
  • Lastpage
    538
  • Abstract
    With the increasing number of security devices and rules in the network, the complexity of detecting and tracing network security configuration errors become a very challenging task. This in turn increases the potential of security breaches due to rule conflicts, requirement violations or lack of security hardening. Most of the existing tools are either limited in scope as they do not offer a global analysis of different network devices or hard to comprehensively use because these tools are not declarative. Declarative logic programming can readily express network configurations and security requirements for verification analysis. In this paper, we use Prolog to model the entire network security configurations including topology, routing, firewall and IPSec. This is implemented in a tool called ConfigAnalyzer, which was also evaluated with large network and policy sizes. The tool allows for verifying reachability and security properties in flexible and expressive manner. It also allows for evaluating security configurations in terms of accessibilities credentials and rules.
  • Keywords
    PROLOG; computer network security; formal verification; reachability analysis; ConfigAnalyzer; Prolog; declarative logic programming; global network security configuration verification; network security configuration error; network security configurations; reachability; Authentication; Decision support systems; Fires; Heating; Logic gates; Routing; declarative language; declarative queries; network configuration; policy verification; security measures;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
  • Conference_Location
    Dublin
  • Print_ISBN
    978-1-4244-9219-0
  • Electronic_ISBN
    978-1-4244-9220-6
  • Type

    conf

  • DOI
    10.1109/INM.2011.5990556
  • Filename
    5990556