Title :
Demonstrating topoS: Theorem-prover-based synthesis of secure network configurations
Author :
Cornelius Diekmann;Andreas Korsten;Georg Carle
Author_Institution :
Technische Universit?t M?nchen
Abstract :
In network management, when it comes to security breaches, human error constitutes a dominant factor. We present our tool topoS which automatically synthesizes low-level network configurations from high-level security goals. The automation and a feedback loop help to prevent human errors. Except for a last serialization step, topoS is formally verified with Isabelle/HOL, which prevents implementation errors. In a case study, we demonstrate topoS by example. For the first time, the complete transition from high-level security goals to both firewall and SDN configurations is presented.
Keywords :
"Servers","Internet","Access control","Manuals","Communication networks","Protocols"
Conference_Titel :
Network and Service Management (CNSM), 2015 11th International Conference on
DOI :
10.1109/CNSM.2015.7367384