• DocumentCode
    145364
  • Title

    Automatic Verification of Security Policies in Firewalls with Dynamic Rule Sequence

  • Author

    Gawanmeh, Amjad

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Khalifa Univ. of Sci., Technol. & Res., Sharjah, United Arab Emirates
  • fYear
    2014
  • fDate
    7-9 April 2014
  • Firstpage
    279
  • Lastpage
    284
  • Abstract
    Security policies play an important role in the security of communication networks. They are normally defined at a high level of abstraction and implemented in firewalls, which are the first defense to secure networks against attacks and unauthorized access. When security policies are implemented in firewalls, anomalities and conflicts that may arise from different policies should be taken into consideration. On the other hand, Firewalls conduct random sequence order shuffling during their operation to prevent certain security attacks. This may result in an incorrect implementation of high level policies that depend on the order of rules inspection in the firewall. This paper presents a formal model of firewall rules sequence and a novel method that verifies the set of security policies when rules sequence changes. The method is tested on synthetic firewall of practical size, where the obtained results demonstrate the ability of firewalls to maintain the functional behavior of security policies during their runtime operation. The detailed analysis shows that the proposed method can be applied on firewalls with dynamic rule sequence in real time.
  • Keywords
    authorisation; firewalls; formal verification; anomality; automatic security policy verification; communication network security; conflict; dynamic rule sequence; firewall rule sequence; firewalls; formal model; network defense; random sequence order shuffling; rule inspection; runtime operation; security attack; unauthorized access; Abstracts; Engines; IP networks; Inspection; Ports (Computers); Dynamic Rule Sequence; Firewall Security Policy; Firewall Verification; Formal Model; Rules Sequence Order;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Technology: New Generations (ITNG), 2014 11th International Conference on
  • Conference_Location
    Las Vegas, NV
  • Print_ISBN
    978-1-4799-3187-3
  • Type

    conf

  • DOI
    10.1109/ITNG.2014.29
  • Filename
    6822211