DocumentCode :
626401
Title :
A Query Driven Security Testing Framework for Enterprise Network
Author :
Bera, P. ; Ghosh, Soumya K.
Author_Institution :
Infosys Labs., Bangalore, India
fYear :
2013
fDate :
18-22 March 2013
Firstpage :
476
Lastpage :
483
Abstract :
Due to extensive use of various network services and web based applications and heterogeneous organizational security requirements; enterprise network configuration is becoming very complex that imposes high operational workload on both regular and experienced administrators. This complexity extensively reduces overall network assurability and usability which in turn make the network vulnerable to various cyber-attacks. Network Access Control Lists (ACLs) is a standard for implementing security configurations in enterprise networks. However, the size and distributed placement of the ACLs in the network impose significant complexity as well as introduce potential scope of security misconfigurations. In this paper, we present a query driven security testing framework to assess the correctness and consistency of the access control list (ACL) based security implementations in an enterprise network. It will allow the network administrators to systematically test the ACL configurations with various interactive service access queries. The framework is built on top of a satisfiability analysis (SAT) engine. The efficacy of the framework is evaluated with extensive experimentations on real and synthetic networks.
Keywords :
authorisation; computability; computer network security; program testing; ACL; SAT engine; Web based application; cyber-attack; enterprise network configuration; heterogeneous organizational security; interactive service access queries; network access control list; network assurability; network usability; query driven security testing; satisfiability analysis; security configuration; Analytical models; Boolean functions; IP networks; Network topology; Security; Testing; Topology; Access Control Lists Satisfiability Analysis; Network Security; Security Testing;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Software Testing, Verification and Validation Workshops (ICSTW), 2013 IEEE Sixth International Conference on
Conference_Location :
Luxembourg
Print_ISBN :
978-1-4799-1324-4
Type :
conf
DOI :
10.1109/ICSTW.2013.62
Filename :
6571673
Link To Document :
بازگشت