• DocumentCode
    3006167
  • Title

    Visualizing firewall configurations using created voids

  • Author

    Morrissey, Shaun P. ; Grinstein, Georges

  • Author_Institution
    Inst. for Visualization & Perception Res., Univ. of Massachusetts, Lowell, MA, USA
  • fYear
    2009
  • fDate
    11-11 Oct. 2009
  • Firstpage
    75
  • Lastpage
    79
  • Abstract
    Security configuration files are created and edited as text files. These files are the essential definition and control of the behavior of security devices. Despite their significant size, complexity, and the possibility of interaction between entries, no visually sophisticated tools exist that explicitly capture and visualize problematic interactions between rules to aid in the comprehension and modification of configuration files. Our initial work on the direct visualization of firewall configurations showed the limitations of visualizing just the range of packets that can be accepted. To visually capture the interactions between rules, we introduce the concept of a "created void." Created voids capture the information about destructive interactions between rules in a firewall ruleset, where an overlap between a deny rule prevents that packet from reaching an accept rule later in the ruleset. We present a lossless five-dimensional visualization of the convex solid decomposition of the set of acceptable packets from a firewall configuration, augmented with visual representations of created voids. This interactive visualization is embedded in a simple firewall ruleset editor, allowing the user to investigate the effect of changes in the ruleset.
  • Keywords
    authorisation; data visualisation; graphical user interfaces; interactive systems; convex solid decomposition; created void; firewall configuration visualization; firewall ruleset; interactive visualization; lossless five-dimensional visualization; security configuration files; visual representations; Visualization; C.2.0 [Computer-Communication Networks]: General - Security and protection (e.g., firewalls); Firewall visualization; H.5.2 [User Interfaces]: Graphical user interfaces (GUI); created void; filtering routers; firewalls; network security; security configuration;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Visualization for Cyber Security, 2009. VizSec 2009. 6th International Workshop on
  • Conference_Location
    Atlantic City, NJ
  • Print_ISBN
    978-1-4244-5413-6
  • Type

    conf

  • DOI
    10.1109/VIZSEC.2009.5375546
  • Filename
    5375546