首页    期刊浏览 2024年11月26日 星期二
登录注册

文章基本信息

  • 标题:Formal Checking of Multiple Firewalls
  • 本地全文:下载
  • 作者:Nihel Ben Youssef ; Adel Bouhoula
  • 期刊名称:International Journal of Computer Science Issues
  • 印刷版ISSN:1694-0784
  • 电子版ISSN:1694-0814
  • 出版年度:2012
  • 卷号:9
  • 期号:3
  • 出版社:IJCSI Press
  • 摘要:When enterprises deploy multiple firewalls, a packet may be examined by different sets of firewalls. It has been observed that the resulting complex firewall network is highly error prone and causes serious security holes. Hence, automated solutions are needed in order to check its correctness. In this paper, we propose a formal and automatic method for checking whether multiple firewalls react correctly with respect to a security policy given in a high level declarative language. When errors are detected, some useful feedback is returned in order to correct the firewall configurations. Furthermore, we propose a priority-based approach to ensure that no incoherencies exist within the security policy. We show that our method is both correct and complete. Finally, it has been implemented in a prototype of verifier based on a satisfiability solver modulo theories. Experiment conducted on relevant case studies demonstrates the efficiency of our approach.
  • 关键词:network security; distributed firewall configuration; formal verification; SMT solver.
国家哲学社会科学文献中心版权所有