Skip to main navigation Skip to search Skip to main content

Inferring higher level policies from firewall rules

  • Alok Tongaonkar
  • , Niranjan Inamdar
  • , R. Sekar
  • Stony Brook University

Research output: Contribution to conferencePaperpeer-review

20 Scopus citations

Abstract

Packet filtering firewall is one of the most important mechanisms used by corporations to enforce their security policy. Recent years have seen a lot of research in the area of firewall management. Typically, firewalls use a large number of low-level filtering rules which are configured using vendor-specific tools. System administrators start off by writing rules which implement the security policy of the organization. They add/delete/change order of rules as the requirements change. For example, when a new machine is added to the network, new rules might be added to the firewall to enable certain services to/from that machine. Making such changes to the low-level rules is complicated by the fact that the effect of a rule is dependent on its priority (usually determined by the position of the rule in the rule set). As the size and complexity of a rule set increases, it becomes difficult to understand the impact of a rule on the rule set. This makes management of rule sets more error prone. This is a very serious problem as errors in firewall configuration mean that the desired security policy is not enforced.

Original languageEnglish
Pages17-26
Number of pages10
StatePublished - 2007
Event21st Large Installation System Administration Conference, LISA 2007 - Dallas, United States
Duration: Nov 11 2007Nov 16 2007

Conference

Conference21st Large Installation System Administration Conference, LISA 2007
Country/TerritoryUnited States
CityDallas
Period11/11/0711/16/07

Fingerprint

Dive into the research topics of 'Inferring higher level policies from firewall rules'. Together they form a unique fingerprint.

Cite this