• DocumentCode
    626401
  • Title

    A Query Driven Security Testing Framework for Enterprise Network

  • Author

    Bera, P. ; Ghosh, Soumya K.

  • Author_Institution
    Infosys Labs., Bangalore, India
  • fYear
    2013
  • fDate
    18-22 March 2013
  • Firstpage
    476
  • Lastpage
    483
  • Abstract
    Due to extensive use of various network services and web based applications and heterogeneous organizational security requirements; enterprise network configuration is becoming very complex that imposes high operational workload on both regular and experienced administrators. This complexity extensively reduces overall network assurability and usability which in turn make the network vulnerable to various cyber-attacks. Network Access Control Lists (ACLs) is a standard for implementing security configurations in enterprise networks. However, the size and distributed placement of the ACLs in the network impose significant complexity as well as introduce potential scope of security misconfigurations. In this paper, we present a query driven security testing framework to assess the correctness and consistency of the access control list (ACL) based security implementations in an enterprise network. It will allow the network administrators to systematically test the ACL configurations with various interactive service access queries. The framework is built on top of a satisfiability analysis (SAT) engine. The efficacy of the framework is evaluated with extensive experimentations on real and synthetic networks.
  • Keywords
    authorisation; computability; computer network security; program testing; ACL; SAT engine; Web based application; cyber-attack; enterprise network configuration; heterogeneous organizational security; interactive service access queries; network access control list; network assurability; network usability; query driven security testing; satisfiability analysis; security configuration; Analytical models; Boolean functions; IP networks; Network topology; Security; Testing; Topology; Access Control Lists Satisfiability Analysis; Network Security; Security Testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation Workshops (ICSTW), 2013 IEEE Sixth International Conference on
  • Conference_Location
    Luxembourg
  • Print_ISBN
    978-1-4799-1324-4
  • Type

    conf

  • DOI
    10.1109/ICSTW.2013.62
  • Filename
    6571673