DocumentCode :
2504942
Title :
A Quadratic, Complete, and Minimal Consistency Diagnosis Process for Firewall ACLs
Author :
Pozo, S. ; Varela-Vaca, A.J. ; Gasca, R.M.
Author_Institution :
Dept. of Comput. Languages & Syst., Univ. of Seville, Sevilla, Spain
fYear :
2010
fDate :
20-23 April 2010
Firstpage :
1037
Lastpage :
1046
Abstract :
Developing and managing firewall Access Control Lists (ACLs) are hard, time-consuming, and error-prone tasks for a variety of reasons. Complexity of networks is constantly increasing, as it is the size of firewall ACLs. Networks have different access control requirements which must be translated by a network administrator into firewall ACLs. During this task, inconsistent rules can be introduced in the ACL. Furthermore, each time a rule is modified (e.g. updated, corrected when a fault is found, etc.) a new inconsistency with other rules can be introduced. An inconsistent firewall ACL implies, in general, a design or development fault, and indicates that the firewall is accepting traffic that should be denied or vice versa. In this paper we propose a complete and minimal consistency diagnosis process which has worst-case quadratic time complexity with the number of rules in a set of inconsistent rules. There are other proposals of consistency diagnosis algorithms. However they have different problems which can prevent their use with big, real-life, ACLs: on the one hand, the minimal ones have exponential worst-case time complexity; on the other hand, the polynomial ones are not minimal.
Keywords :
authorisation; computer network security; diagnosis process; exponential worst-case time complexity; firewall ACL; firewall access control list; quadratic time complexity; Access control; Application software; Computer languages; Educational institutions; Error correction; Fault diagnosis; Polynomials; Proposals; Resource management; Systems engineering and theory; acl; anomaly; conflict; detection; diagnosis; firewall; inconsistency; management; minimal; ruleset;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Information Networking and Applications (AINA), 2010 24th IEEE International Conference on
Conference_Location :
Perth, WA
ISSN :
1550-445X
Print_ISBN :
978-1-4244-6695-5
Type :
conf
DOI :
10.1109/AINA.2010.63
Filename :
5474827
Link To Document :
بازگشت