• DocumentCode
    2504942
  • Title

    A Quadratic, Complete, and Minimal Consistency Diagnosis Process for Firewall ACLs

  • Author

    Pozo, S. ; Varela-Vaca, A.J. ; Gasca, R.M.

  • Author_Institution
    Dept. of Comput. Languages & Syst., Univ. of Seville, Sevilla, Spain
  • fYear
    2010
  • fDate
    20-23 April 2010
  • Firstpage
    1037
  • Lastpage
    1046
  • Abstract
    Developing and managing firewall Access Control Lists (ACLs) are hard, time-consuming, and error-prone tasks for a variety of reasons. Complexity of networks is constantly increasing, as it is the size of firewall ACLs. Networks have different access control requirements which must be translated by a network administrator into firewall ACLs. During this task, inconsistent rules can be introduced in the ACL. Furthermore, each time a rule is modified (e.g. updated, corrected when a fault is found, etc.) a new inconsistency with other rules can be introduced. An inconsistent firewall ACL implies, in general, a design or development fault, and indicates that the firewall is accepting traffic that should be denied or vice versa. In this paper we propose a complete and minimal consistency diagnosis process which has worst-case quadratic time complexity with the number of rules in a set of inconsistent rules. There are other proposals of consistency diagnosis algorithms. However they have different problems which can prevent their use with big, real-life, ACLs: on the one hand, the minimal ones have exponential worst-case time complexity; on the other hand, the polynomial ones are not minimal.
  • Keywords
    authorisation; computer network security; diagnosis process; exponential worst-case time complexity; firewall ACL; firewall access control list; quadratic time complexity; Access control; Application software; Computer languages; Educational institutions; Error correction; Fault diagnosis; Polynomials; Proposals; Resource management; Systems engineering and theory; acl; anomaly; conflict; detection; diagnosis; firewall; inconsistency; management; minimal; ruleset;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications (AINA), 2010 24th IEEE International Conference on
  • Conference_Location
    Perth, WA
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-4244-6695-5
  • Type

    conf

  • DOI
    10.1109/AINA.2010.63
  • Filename
    5474827