DocumentCode
3145867
Title
Analyzing and resolving anomalies in firewall security policies based on propositional logic
Author
Rezvani, Mohsen ; Aryan, Ramtin
Author_Institution
Dept. of IT & Comput. Eng., Shahrood Univ. of Technol., Shahrood, Iran
fYear
2009
fDate
14-15 Dec. 2009
Firstpage
1
Lastpage
7
Abstract
Firewalls are essential components in network security solutions. In order to implement correct security policy, the anomalies in firewall rules should be analyzed carefully, especially in enterprise network. In this paper, we present a new formal framework for analysis and resolution of anomalies in firewall rules. First of all, a formal model based on propositional logic is presented to specify rules. Then we specify all anomalies that identified in the latest researches based on our model. Current studies for analysis of anomalies are based on one to one rule anomalies, but we identify total version of anomalies based on one to many relationship of rules. Furthermore we have designed and implemented a tool based on theorem proving for verification of the specified anomalies. In addition, we present two algorithms for resolving anomalies in a rule database based on our formal model. These algorithms minimize the number of rules without changing the policy. Experimental results indicate that our algorithms for discovery single and total anomalies run in 2-3 seconds for a very large firewall with thousands of rules.
Keywords
database management systems; security of data; theorem proving; anomalies; enterprise network; firewall security policies; formal model; network security solutions; propositional logic; rule database; theorem proving; Algorithm design and analysis; Binary decision diagrams; Boolean functions; Computer security; Data security; Data structures; Databases; Detection algorithms; Logic; Virtual private networks; Anomaly; Firewall; Resolving Anomaly; Rule Database; Total Anomaly;
fLanguage
English
Publisher
ieee
Conference_Titel
Multitopic Conference, 2009. INMIC 2009. IEEE 13th International
Conference_Location
Islamabad
Print_ISBN
978-1-4244-4872-2
Electronic_ISBN
978-1-4244-4873-9
Type
conf
DOI
10.1109/INMIC.2009.5383125
Filename
5383125
Link To Document