Title :
Analyzing and resolving anomalies in firewall security policies based on propositional logic
Author :
Rezvani, Mohsen ; Aryan, Ramtin
Author_Institution :
Dept. of IT & Comput. Eng., Shahrood Univ. of Technol., Shahrood, Iran
Abstract :
Firewalls are essential components in network security solutions. In order to implement correct security policy, the anomalies in firewall rules should be analyzed carefully, especially in enterprise network. In this paper, we present a new formal framework for analysis and resolution of anomalies in firewall rules. First of all, a formal model based on propositional logic is presented to specify rules. Then we specify all anomalies that identified in the latest researches based on our model. Current studies for analysis of anomalies are based on one to one rule anomalies, but we identify total version of anomalies based on one to many relationship of rules. Furthermore we have designed and implemented a tool based on theorem proving for verification of the specified anomalies. In addition, we present two algorithms for resolving anomalies in a rule database based on our formal model. These algorithms minimize the number of rules without changing the policy. Experimental results indicate that our algorithms for discovery single and total anomalies run in 2-3 seconds for a very large firewall with thousands of rules.
Keywords :
database management systems; security of data; theorem proving; anomalies; enterprise network; firewall security policies; formal model; network security solutions; propositional logic; rule database; theorem proving; Algorithm design and analysis; Binary decision diagrams; Boolean functions; Computer security; Data security; Data structures; Databases; Detection algorithms; Logic; Virtual private networks; Anomaly; Firewall; Resolving Anomaly; Rule Database; Total Anomaly;
Conference_Titel :
Multitopic Conference, 2009. INMIC 2009. IEEE 13th International
Conference_Location :
Islamabad
Print_ISBN :
978-1-4244-4872-2
Electronic_ISBN :
978-1-4244-4873-9
DOI :
10.1109/INMIC.2009.5383125