DocumentCode :
576957
Title :
Test tool for equivalence of access control list
Author :
Sayama, Hirokazu ; Yoshiura, Noriaki
Author_Institution :
Dept. of Inf. & Comput. Sci., Saitama Univ., Saitama, Japan
fYear :
2012
fDate :
25-27 Sept. 2012
Firstpage :
1
Lastpage :
4
Abstract :
Computer network security is one of the important issues in the Internet age. Network administrators of organizations such as companies or universities filter IP packets at network equipment such as Layer 3 switch or firewall between their organizations and the Internet to keep the security of the computer networks. One of the expressions of the filtering rules of IP packets is access control list. Access control lists are lists of rules, which describe permission or denial of packet transition based on source IP address, destination IP address, port numbers and so on. Access control lists are not always fixed; network administrators change access control lists according to the change of network topology or network security policy. After several changes, access control lists may include redundancies and network administrators have to modify the access control list to remove redundancies. This modification must keep the semantics of access control list. After modification, the network administrators must confirm that the semantics of access control list does not change. One of the methods of equivalence of two access control lists is to send test IP packets to the network equipment that filters IP packets and to check the transitions of the IP packets. This paper proposes the method of generating test packets to confirm the equivalence of two access control lists.
Keywords :
IP networks; Internet; authorisation; computer network security; telecommunication equipment; telecommunication network topology; IP packet; Internet; access control list; computer network security policy; destination IP address; equivalence test tool; filtering rules; layer 3 switch; network equipment; network topology; packet transition; port number; semantics; Access control; Educational institutions; Hardware; IP networks; Internet; Access Control List; Computer Network Security; Network Operation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Network Operations and Management Symposium (APNOMS), 2012 14th Asia-Pacific
Conference_Location :
Seoul
Print_ISBN :
978-1-4673-4494-4
Electronic_ISBN :
978-1-4673-4495-1
Type :
conf
DOI :
10.1109/APNOMS.2012.6356103
Filename :
6356103
Link To Document :
بازگشت