DocumentCode :
1330062
Title :
Minimizing the Maximum Firewall Rule Set in a Network with Multiple Firewalls
Author :
Yoon, MyungKeun ; Chen, Shigang ; Zhang, Zhan
Author_Institution :
Korea Financial Telecommun. & Clearings Inst., Seoul, South Korea
Volume :
59
Issue :
2
fYear :
2010
Firstpage :
218
Lastpage :
230
Abstract :
A firewall´s complexity is known to increase with the size of its rule set. Empirical studies show that as the rule set grows larger, the number of configuration errors on a firewall increases sharply, while the performance of the firewall degrades. When designing a security-sensitive network, it is critical to construct the network topology and its routing structure carefully in order to reduce the firewall rule sets, which helps lower the chance of security loopholes and prevent performance bottleneck. This paper studies the problems of how to place the firewalls in a topology during network design and how to construct the routing tables during operation such that the maximum firewall rule set can be minimized. These problems have not been studied adequately despite their importance. We have two major contributions. First, we prove that the problems are NP-complete. Second, we propose a heuristic solution and demonstrate the effectiveness of the algorithm by simulations. The results show that the proposed algorithm reduces the maximum firewall rule set by 2-5 times when comparing with other algorithms.
Keywords :
authorisation; communication complexity; computer network performance evaluation; telecommunication network management; telecommunication network routing; telecommunication network topology; telecommunication security; NP-complete; configuration errors; firewall complexity; maximum firewall rule set; network design; network topology; routing structure; routing tables; security loopholes; security-sensitive network; Access control; Access protocols; Computer errors; Computer science; Degradation; Intrusion detection; Multidimensional systems; Network topology; Routing; Telecommunication network topology; Virtual private networks; Wool; Firewall configuration; access control rules; network security.;
fLanguage :
English
Journal_Title :
Computers, IEEE Transactions on
Publisher :
ieee
ISSN :
0018-9340
Type :
jour
DOI :
10.1109/TC.2009.172
Filename :
5332225
Link To Document :
بازگشت