DocumentCode :
3570847
Title :
Detecting and resolving inconsistencies in firewalls
Author :
Du Zhang ; Jujjavarapu, Lavanya ; Meiliu Lu
Author_Institution :
Dept. of Comput. Sci., California State Univ., Sacramento, CA, USA
fYear :
2014
Firstpage :
1
Lastpage :
7
Abstract :
Firewalls are a defense mechanism for network security. Today, firewalls have played a pivotal role in a wide spectrum of circumstances, from enterprise networks to home networks. Firewall rules have their execution semantics. Firewalls are often networked to establish perimeters for different parts of an enterprise with differing security policy requirements. Hence, rules in intra-firewall and inter-firewall settings interact, sometimes creating unintended side-effects. The complexity in utilizing firewalls to implement consistent and coherent security policies to safeguard enterprise networks poses great challenges to the network security as a whole. A major challenge is firewall inconsistencies that compromise the effectiveness of firewall protection. In this paper, we propose an approach to detecting and resolving major types of firewall inconsistencies. We describe our detection algorithms and resolution strategies to firewall inconsistencies, and report some initial results of a tool implementing the proposed approach. The main contribution of our work lies in the fact that our approach takes advantage of two necessary conditions in firewall inconsistencies, resulting in a more effective detection method.
Keywords :
firewalls; detection algorithms; enterprise networks; execution semantics; firewall inconsistencies; firewall protection; home networks; network security; resolution strategies; security policy requirements; Communication networks; Computer crime; Detection algorithms; Electronics packaging; Firewalls (computing); Protocols; access control lists; detection and resolution of firewall inconsistencies; firewall inconsistencies; firewall path; firewalls;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Reuse and Integration (IRI), 2014 IEEE 15th International Conference on
Type :
conf
DOI :
10.1109/IRI.2014.7051864
Filename :
7051864
Link To Document :
بازگشت