DocumentCode
3148237
Title
Diverse firewall design
Author
Liu, Alex X. ; Gouda, Mohamed G.
Author_Institution
Dept. of Comput. Sci., Texas Univ., Austin, TX, USA
fYear
2004
fDate
28 June-1 July 2004
Firstpage
595
Lastpage
604
Abstract
Firewalls are safety-critical systems that secure most private networks. An error in a firewall either leaks secret information from its network or disrupts legitimate communication between its network and the rest of the Internet. How to design a correct firewall is therefore an important issue. In this paper, we propose the method of diverse firewall design, which is inspired by the well-known method of design diversity for building fault-tolerant software. Our method consists of two phases: a design phase and a comparison phase. In the design phase, the same requirement specification of a firewall is given to multiple teams who proceed independently to design different versions of the firewall. In the comparison phase, the resulting multiple versions are compared with each other to find out all the discrepancies between them, then each discrepancy is further investigated and a correction is applied if necessary. The technical challenge in the method of diverse firewall design is how to discover all the discrepancies between two given firewalls. We present a series of three efficient algorithms for solving this problem: (I) a construction algorithm for constructing an equivalent ordered firewall decision diagram from a sequence of rules, (2) a shaping algorithm for transforming two ordered firewall decision diagrams to become semi-isomorphic without changing their semantics, and (3) a comparison algorithm for detecting all the discrepancies between two semi-isomorphic firewall decision diagrams.
Keywords
Internet; authorisation; computer networks; data privacy; safety-critical software; Internet; comparison algorithm; construction algorithm; fault-tolerant software; firewall decision diagram; firewalls; information secrecy; private networks security; safety-critical systems; shaping algorithm; Buildings; Computer errors; Computer networks; Design methodology; Diversity methods; Fault tolerance; IP networks; Natural languages; Protocols;
fLanguage
English
Publisher
ieee
Conference_Titel
Dependable Systems and Networks, 2004 International Conference on
Print_ISBN
0-7695-2052-9
Type
conf
DOI
10.1109/DSN.2004.1311930
Filename
1311930
Link To Document