DocumentCode :
2843005
Title :
A declarative approach for global network security configuration verification and evaluation
Author :
Rahman, Mohammad Ashiqur ; Al-Shaer, Ehab
Author_Institution :
Dept. of Software & Inf. Syst., Univ. of North Carolina at Charlotte, Charlotte, NC, USA
fYear :
2011
fDate :
23-27 May 2011
Firstpage :
531
Lastpage :
538
Abstract :
With the increasing number of security devices and rules in the network, the complexity of detecting and tracing network security configuration errors become a very challenging task. This in turn increases the potential of security breaches due to rule conflicts, requirement violations or lack of security hardening. Most of the existing tools are either limited in scope as they do not offer a global analysis of different network devices or hard to comprehensively use because these tools are not declarative. Declarative logic programming can readily express network configurations and security requirements for verification analysis. In this paper, we use Prolog to model the entire network security configurations including topology, routing, firewall and IPSec. This is implemented in a tool called ConfigAnalyzer, which was also evaluated with large network and policy sizes. The tool allows for verifying reachability and security properties in flexible and expressive manner. It also allows for evaluating security configurations in terms of accessibilities credentials and rules.
Keywords :
PROLOG; computer network security; formal verification; reachability analysis; ConfigAnalyzer; Prolog; declarative logic programming; global network security configuration verification; network security configuration error; network security configurations; reachability; Authentication; Decision support systems; Fires; Heating; Logic gates; Routing; declarative language; declarative queries; network configuration; policy verification; security measures;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Integrated Network Management (IM), 2011 IFIP/IEEE International Symposium on
Conference_Location :
Dublin
Print_ISBN :
978-1-4244-9219-0
Electronic_ISBN :
978-1-4244-9220-6
Type :
conf
DOI :
10.1109/INM.2011.5990556
Filename :
5990556
Link To Document :
بازگشت