DocumentCode
2457465
Title
Network Security Policies: Verification, Optimization and Testing
Author
Al-Shaer, Ehab
Author_Institution
Sch. of Comput. Sci., Telecommun. & Inf. Syst., DePaul Univ., Chicago, IL
fYear
2006
fDate
3-7 April 2006
Firstpage
584
Lastpage
584
Abstract
Summary form only given. The importance of network security has been significantly increasing in the past few years. However, the increasing complexity of managing security polices particularly in enterprise networks poses real challenge for efficient security solutions. Network security perimeters such as Firewalls, IPSec gateways, intrusion detection and prevention systems operate based on locally configured policies. Yet these policies are not necessarily autonomous and might interact between each other to construct a global network security policy. Due to manual, distributed and uncoordinated configuration of security polices, rules conflicts and policy inconsistency are created, causing serious network security vulnerabilities. In addition, enterprise networks continuously grow in size and complexity, which makes policy modification, inspection and evaluation nightmare. Addressing these issues is a key requirement for obtaining provable security and seamless policy configuration. In addition, with growth in network speed and size, the need to optimize the security policy to cope with the traffic rate and attacks is significantly increasing. The constant evolution of policy syntax and semantics make the functional testing of these devices for vulnerability penetration is a difficult task. This tutorial is divided into three parts. In the first part, we will present techniques to automatically verify and correct firewall and IPSec/VPN polices in large-scale enterprise networks. In the second part, we will discuss techniques to enhance and optimize the policy structure and rule ordering in order to reduce packet matching and improve significantly firewall and IPSec performance. In the third part, we will present techniques that can be used by users, service provider as well as vendors to test their security devices efficiently and accurately
Keywords
IP networks; business communication; telecommunication security; virtual private networks; IPSec; VPN; enterprise networks; firewall; functional testing; network security policies; packet matching; policy syntax; semantics; service provider; vulnerability penetration; Computer network management; Computer science; Computer security; Computerized monitoring; Information security; Inspection; Intrusion detection; Management information systems; Telecommunication traffic; Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Network Operations and Management Symposium, 2006. NOMS 2006. 10th IEEE/IFIP
Conference_Location
Vancouver, BC
ISSN
1542-1201
Print_ISBN
1-4244-0142-9
Type
conf
DOI
10.1109/NOMS.2006.1687592
Filename
1687592
Link To Document