• DocumentCode
    2487228
  • Title

    Network configuration in a box: towards end-to-end verification of network reachability and security

  • Author

    Al-Shaer, Ehab ; Marrero, Will ; El-Atawy, Adel ; Elbadawi, Khalid

  • Author_Institution
    Dept. of Software & Inf. Syst., Univ. of North Carolina at Charlotte, Charlotte, NC, USA
  • fYear
    2009
  • fDate
    13-16 Oct. 2009
  • Firstpage
    123
  • Lastpage
    132
  • Abstract
    Recent studies show that configurations of network access control is one of the most complex and error prone network management tasks. For this reason, network misconfiguration becomes the main source for network unreachablility and vulnerability problems. In this paper, we present a novel approach that models the global end-to-end behavior of access control configurations of the entire network including routers, IPSec, firewalls, and NAT for unicast and multicast packets. Our model represents the network as a state machine where the packet header and location determines the state. The transitions in this model are determined by packet header information, packet location, and policy semantics for the devices being modeled. We encode the semantics of access control policies with Boolean functions using binary decision diagrams (BDDs). We then use computation tree logic (CTL) and symbolic model checking to investigate all future and past states of this packet in the network and verify network reachability and security requirements. Thus, our contributions in this work is the global encoding for network configurations that allows for general reachability and security property-based verification using CTL model checking. We have implemented our approach in a tool called ConfigChecker. While evaluating ConfigChecker, we modeled and verified network configurations with thousands of devices and millions of configuration rules, thus demonstrating the scalability of this approach.
  • Keywords
    telecommunication network management; telecommunication security; Boolean function; ConfigChecker; IPSec; binary decision diagram; computation tree logic; error prone network management task; firewalls; multicast packet; network access control; network configuration; network reachability; network security; packet header information; packet location; policy semantics; routers; security property-based verification; state machine; symbolic model checking; unicast packet; Access control; Boolean functions; Computer networks; Data structures; Encoding; Error correction; Logic devices; Network address translation; Scalability; Unicast;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network Protocols, 2009. ICNP 2009. 17th IEEE International Conference on
  • Conference_Location
    Princeton, NJ
  • ISSN
    1092-1648
  • Print_ISBN
    978-1-4244-4635-3
  • Electronic_ISBN
    1092-1648
  • Type

    conf

  • DOI
    10.1109/ICNP.2009.5339690
  • Filename
    5339690