• DocumentCode
    564522
  • Title

    Firewall configuration management using XACML policies

  • Author

    Tuglular, Tugkan ; Cetin, Fusun ; Yarimtepe, Oguz ; Gercek, Gurcan

  • Author_Institution
    Department of Computer Engineering, Izmir Institute of Technology, Gulbahce Koyu, Urla, Turkey
  • Volume
    Supplement
  • fYear
    2008
  • fDate
    Sept. 28 2008-Oct. 2 2008
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    This paper proposes an architecture for XACML based management of firewall configurations in large enterprise networks. The goal of this architecture is to allow administrators and end-users to manage their firewalls, while enforcement of organizational policy is ensured to prevent unacceptable traffic gaining access to the private network domain. The central architectural component is the domain policy server which pushes organizational policy down to firewalls deployed in its domain. In addition to its reporting function, the domain policy server monitors and verifies policy changes, i.e. checks for inter- and intrafirewall anomalies, on any firewall within its domain. The proposed architecture includes firewall agent components, where one resides on each firewall, through which coordinated operations on firewall policies are achievable. Firewall policies, topologies, and configuration messages that are stored and exchanged within the architecture are presented in XML. Although available XACML is used for the representation of firewall policies, two DTDs are developed to express topologies and configuration messages. A prototype implementation of this architecture is presented in this paper along with examples of firewall configuration management operations.
  • Keywords
    Fires; Network topology; Prototypes; Security; Servers; Topology; XML;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Telecommunications Network Strategy and Planning Symposium, 2008. Networks 2008. The 13th International
  • Conference_Location
    Budapest
  • Print_ISBN
    978-963-8111-68-5
  • Type

    conf

  • DOI
    10.1109/NETWKS.2008.6231365
  • Filename
    6231365