DocumentCode :
1806878
Title :
FIREMAN: a toolkit for firewall modeling and analysis
Author :
Yuan, Lihua ; Chen, Hao ; Mai, Jianning ; Chuah, Chen-Nee ; Su, Zhendong ; Mohapatra, Prasant
Author_Institution :
California Univ., Davis, CA
fYear :
2006
fDate :
21-24 May 2006
Lastpage :
213
Abstract :
Security concerns are becoming increasingly critical in networked systems. Firewalls provide important defense for network security. However, misconfigurations in firewalls are very common and significantly weaken the desired security. This paper introduces FIREMAN, a static analysis toolkit for firewall modeling and analysis. By treating firewall configurations as specialized programs, FIREMAN applies static analysis techniques to check misconfigurations, such as policy violations, inconsistencies, and inefficiencies, in individual firewalls as well as among distributed firewalls. FIREMAN performs symbolic model checking of the firewall configurations for all possible IP packets and along all possible data paths. It is both sound and complete because of the finite state nature of firewall configurations. FIREMAN is implemented by modeling firewall rules using binary decision diagrams (BDDs), which have been used successfully in hardware verification and model checking. We have experimented with FIREMAN and used it to uncover several real misconfigurations in enterprise networks, some of which have been subsequently confirmed and corrected by the administrators of these networks
Keywords :
program diagnostics; security of data; software tools; FIREMAN; binary decision diagrams; distributed firewalls; enterprise networks; firewall analysis; firewall modeling; misconfiguration checking; network security; networked systems; policy violations; static analysis toolkit; symbolic model checking; Boolean functions; Data privacy; Data security; Data structures; Filtering; Hardware; Production; Routing; Telecommunication traffic; Wool;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Privacy, 2006 IEEE Symposium on
Conference_Location :
Berkeley/Oakland, CA
ISSN :
1081-6011
Print_ISBN :
0-7695-2574-1
Type :
conf
DOI :
10.1109/SP.2006.16
Filename :
1624012
Link To Document :
بازگشت