DocumentCode
145364
Title
Automatic Verification of Security Policies in Firewalls with Dynamic Rule Sequence
Author
Gawanmeh, Amjad
Author_Institution
Dept. of Electr. & Comput. Eng., Khalifa Univ. of Sci., Technol. & Res., Sharjah, United Arab Emirates
fYear
2014
fDate
7-9 April 2014
Firstpage
279
Lastpage
284
Abstract
Security policies play an important role in the security of communication networks. They are normally defined at a high level of abstraction and implemented in firewalls, which are the first defense to secure networks against attacks and unauthorized access. When security policies are implemented in firewalls, anomalities and conflicts that may arise from different policies should be taken into consideration. On the other hand, Firewalls conduct random sequence order shuffling during their operation to prevent certain security attacks. This may result in an incorrect implementation of high level policies that depend on the order of rules inspection in the firewall. This paper presents a formal model of firewall rules sequence and a novel method that verifies the set of security policies when rules sequence changes. The method is tested on synthetic firewall of practical size, where the obtained results demonstrate the ability of firewalls to maintain the functional behavior of security policies during their runtime operation. The detailed analysis shows that the proposed method can be applied on firewalls with dynamic rule sequence in real time.
Keywords
authorisation; firewalls; formal verification; anomality; automatic security policy verification; communication network security; conflict; dynamic rule sequence; firewall rule sequence; firewalls; formal model; network defense; random sequence order shuffling; rule inspection; runtime operation; security attack; unauthorized access; Abstracts; Engines; IP networks; Inspection; Ports (Computers); Dynamic Rule Sequence; Firewall Security Policy; Firewall Verification; Formal Model; Rules Sequence Order;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Technology: New Generations (ITNG), 2014 11th International Conference on
Conference_Location
Las Vegas, NV
Print_ISBN
978-1-4799-3187-3
Type
conf
DOI
10.1109/ITNG.2014.29
Filename
6822211
Link To Document