DocumentCode
626401
Title
A Query Driven Security Testing Framework for Enterprise Network
Author
Bera, P. ; Ghosh, Soumya K.
Author_Institution
Infosys Labs., Bangalore, India
fYear
2013
fDate
18-22 March 2013
Firstpage
476
Lastpage
483
Abstract
Due to extensive use of various network services and web based applications and heterogeneous organizational security requirements; enterprise network configuration is becoming very complex that imposes high operational workload on both regular and experienced administrators. This complexity extensively reduces overall network assurability and usability which in turn make the network vulnerable to various cyber-attacks. Network Access Control Lists (ACLs) is a standard for implementing security configurations in enterprise networks. However, the size and distributed placement of the ACLs in the network impose significant complexity as well as introduce potential scope of security misconfigurations. In this paper, we present a query driven security testing framework to assess the correctness and consistency of the access control list (ACL) based security implementations in an enterprise network. It will allow the network administrators to systematically test the ACL configurations with various interactive service access queries. The framework is built on top of a satisfiability analysis (SAT) engine. The efficacy of the framework is evaluated with extensive experimentations on real and synthetic networks.
Keywords
authorisation; computability; computer network security; program testing; ACL; SAT engine; Web based application; cyber-attack; enterprise network configuration; heterogeneous organizational security; interactive service access queries; network access control list; network assurability; network usability; query driven security testing; satisfiability analysis; security configuration; Analytical models; Boolean functions; IP networks; Network topology; Security; Testing; Topology; Access Control Lists Satisfiability Analysis; Network Security; Security Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Testing, Verification and Validation Workshops (ICSTW), 2013 IEEE Sixth International Conference on
Conference_Location
Luxembourg
Print_ISBN
978-1-4799-1324-4
Type
conf
DOI
10.1109/ICSTW.2013.62
Filename
6571673
Link To Document