DocumentCode
3570847
Title
Detecting and resolving inconsistencies in firewalls
Author
Du Zhang ; Jujjavarapu, Lavanya ; Meiliu Lu
Author_Institution
Dept. of Comput. Sci., California State Univ., Sacramento, CA, USA
fYear
2014
Firstpage
1
Lastpage
7
Abstract
Firewalls are a defense mechanism for network security. Today, firewalls have played a pivotal role in a wide spectrum of circumstances, from enterprise networks to home networks. Firewall rules have their execution semantics. Firewalls are often networked to establish perimeters for different parts of an enterprise with differing security policy requirements. Hence, rules in intra-firewall and inter-firewall settings interact, sometimes creating unintended side-effects. The complexity in utilizing firewalls to implement consistent and coherent security policies to safeguard enterprise networks poses great challenges to the network security as a whole. A major challenge is firewall inconsistencies that compromise the effectiveness of firewall protection. In this paper, we propose an approach to detecting and resolving major types of firewall inconsistencies. We describe our detection algorithms and resolution strategies to firewall inconsistencies, and report some initial results of a tool implementing the proposed approach. The main contribution of our work lies in the fact that our approach takes advantage of two necessary conditions in firewall inconsistencies, resulting in a more effective detection method.
Keywords
firewalls; detection algorithms; enterprise networks; execution semantics; firewall inconsistencies; firewall protection; home networks; network security; resolution strategies; security policy requirements; Communication networks; Computer crime; Detection algorithms; Electronics packaging; Firewalls (computing); Protocols; access control lists; detection and resolution of firewall inconsistencies; firewall inconsistencies; firewall path; firewalls;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Reuse and Integration (IRI), 2014 IEEE 15th International Conference on
Type
conf
DOI
10.1109/IRI.2014.7051864
Filename
7051864
Link To Document