• DocumentCode
    3145867
  • Title

    Analyzing and resolving anomalies in firewall security policies based on propositional logic

  • Author

    Rezvani, Mohsen ; Aryan, Ramtin

  • Author_Institution
    Dept. of IT & Comput. Eng., Shahrood Univ. of Technol., Shahrood, Iran
  • fYear
    2009
  • fDate
    14-15 Dec. 2009
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    Firewalls are essential components in network security solutions. In order to implement correct security policy, the anomalies in firewall rules should be analyzed carefully, especially in enterprise network. In this paper, we present a new formal framework for analysis and resolution of anomalies in firewall rules. First of all, a formal model based on propositional logic is presented to specify rules. Then we specify all anomalies that identified in the latest researches based on our model. Current studies for analysis of anomalies are based on one to one rule anomalies, but we identify total version of anomalies based on one to many relationship of rules. Furthermore we have designed and implemented a tool based on theorem proving for verification of the specified anomalies. In addition, we present two algorithms for resolving anomalies in a rule database based on our formal model. These algorithms minimize the number of rules without changing the policy. Experimental results indicate that our algorithms for discovery single and total anomalies run in 2-3 seconds for a very large firewall with thousands of rules.
  • Keywords
    database management systems; security of data; theorem proving; anomalies; enterprise network; firewall security policies; formal model; network security solutions; propositional logic; rule database; theorem proving; Algorithm design and analysis; Binary decision diagrams; Boolean functions; Computer security; Data security; Data structures; Databases; Detection algorithms; Logic; Virtual private networks; Anomaly; Firewall; Resolving Anomaly; Rule Database; Total Anomaly;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Multitopic Conference, 2009. INMIC 2009. IEEE 13th International
  • Conference_Location
    Islamabad
  • Print_ISBN
    978-1-4244-4872-2
  • Electronic_ISBN
    978-1-4244-4873-9
  • Type

    conf

  • DOI
    10.1109/INMIC.2009.5383125
  • Filename
    5383125