File Download

There are no files associated with this item.

  Links for fulltext
     (May Require Subscription)
Supplementary

Conference Paper: FIREMAN: A toolkit for firewall modeling and analysis

TitleFIREMAN: A toolkit for firewall modeling and analysis
Authors
Issue Date2006
Citation
Proceedings - IEEE Symposium on Security and Privacy, 2006, v. 2006, p. 199-213 How to Cite?
AbstractSecurity concerns are becoming increasingly critical in networked systems. Firewalls provide important defense for network security. However, misconfigurations in firewalls are very common and significantly weaken the desired security. This paper introduces FIREMAN, a static analysis toolkit for firewall modeling and analysis. By treating firewall configurations as specialized programs, FIREMAN applies static analysis techniques to check misconfigurations, such as policy violations, inconsistencies, and inefficiencies, in individual firewalls as well as among distributed firewalls. FIREMAN performs symbolic model checking of the firewall configurations for all possible IP packets and along all possible datapaths. It is both sound and complete because of the finite state nature of firewall configurations. FIREMAN is implemented by modeling firewall rules using binary decision diagrams (BDDs), which have been used successfully in hardware verification and model checking. We have experimented with FIREMAN and used it to uncover several real misconfigurations in enterprise networks, some of which have been subsequently confirmed and corrected by the administrators of these networks. © 2006 IEEE.
Persistent Identifierhttp://hdl.handle.net/10722/346538
ISSN
2020 SCImago Journal Rankings: 2.407

 

DC FieldValueLanguage
dc.contributor.authorYuan, Lihua-
dc.contributor.authorChen, Hao-
dc.contributor.authorMai, Jianning-
dc.contributor.authorChuah, Chen Nee-
dc.contributor.authorSu, Zhendong-
dc.contributor.authorMohapatra, Prasant-
dc.date.accessioned2024-09-17T04:11:35Z-
dc.date.available2024-09-17T04:11:35Z-
dc.date.issued2006-
dc.identifier.citationProceedings - IEEE Symposium on Security and Privacy, 2006, v. 2006, p. 199-213-
dc.identifier.issn1081-6011-
dc.identifier.urihttp://hdl.handle.net/10722/346538-
dc.description.abstractSecurity concerns are becoming increasingly critical in networked systems. Firewalls provide important defense for network security. However, misconfigurations in firewalls are very common and significantly weaken the desired security. This paper introduces FIREMAN, a static analysis toolkit for firewall modeling and analysis. By treating firewall configurations as specialized programs, FIREMAN applies static analysis techniques to check misconfigurations, such as policy violations, inconsistencies, and inefficiencies, in individual firewalls as well as among distributed firewalls. FIREMAN performs symbolic model checking of the firewall configurations for all possible IP packets and along all possible datapaths. It is both sound and complete because of the finite state nature of firewall configurations. FIREMAN is implemented by modeling firewall rules using binary decision diagrams (BDDs), which have been used successfully in hardware verification and model checking. We have experimented with FIREMAN and used it to uncover several real misconfigurations in enterprise networks, some of which have been subsequently confirmed and corrected by the administrators of these networks. © 2006 IEEE.-
dc.languageeng-
dc.relation.ispartofProceedings - IEEE Symposium on Security and Privacy-
dc.titleFIREMAN: A toolkit for firewall modeling and analysis-
dc.typeConference_Paper-
dc.description.naturelink_to_subscribed_fulltext-
dc.identifier.doi10.1109/SP.2006.16-
dc.identifier.scopuseid_2-s2.0-33751028760-
dc.identifier.volume2006-
dc.identifier.spage199-
dc.identifier.epage213-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats