DocumentCode
2207279
Title
Simultaneous Analysis of Time and Space for Conflict Detection in Time-Based Firewall Policies
Author
Thanasegaran, Subana ; Tateiwa, Yuichiro ; Katayama, Yoshiaki ; Takahashi, Naohisa
Author_Institution
Dept. of Comput. Sci. & Eng., Nagoya Inst. of Technol., Nagoya, Japan
fYear
2010
fDate
June 29 2010-July 1 2010
Firstpage
1015
Lastpage
1021
Abstract
Firewalls are one of the most deployed mechanisms to protect the network from unauthorized access and security threats. However, maintenance of firewall policy is an error-prone and complicated task for a dynamic network environment. Conflict is a misconfiguration that happens when a packet matches two or more filters resulting in shadowing and redundancy of the filters. Network administrators reconfigure the filters to minimize the effect of conflicts, as the filters do not reflect for what it was intended. Nowadays, time-based filters are used in CISCO firewalls and LINUX Iptables to control network traffic in time. Conflict occurs when a packet matches two or more time-based filters active in the same timing. Detection of conflicts in time-based filters is necessary, because the existing conflict detection techniques turns ineffective, as analysis of filters in time is not considered. This problem is not been addressed in research regardless of its significance. To resolve it, in this paper, we propose an n+1 dimensional approach (n refers the number of key fields in a packet header) to detect conflicts by analyzing time and space simultaneously. We compute characterization vectors to detect the conflicting filters which discards the non-conflicting filters in the initial stage of computation and remove the unnecessary steps. Further, we implemented a prototype system and conducted experiments on time-based filters with and without considering time. We found that approximately 50% of conflicting filters becomes non-conflicting when time is considered. Hence, our conflict detection system for time-based filters reduces the workload of the administrator as the filters for reconfiguration is considerably reduced.
Keywords
Linux; authorisation; computer network security; CISCO firewalls; conflict detection; dynamic network environment; network administrators; packet matches; simultaneous analysis; time based firewall policies; Active filters; Fires; IP networks; Information filters; Matched filters; Topology; Packet filtering; firewall mis-configuration; time-based rules;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer and Information Technology (CIT), 2010 IEEE 10th International Conference on
Conference_Location
Bradford
Print_ISBN
978-1-4244-7547-6
Type
conf
DOI
10.1109/CIT.2010.186
Filename
5578622
Link To Document