Skip to main navigation Skip to search Skip to main content

Tri-modularization of firewall policies

  • Haining Chen
  • , Omar Chowdhury
  • , Ninghui Li
  • , Warut Khern-Am-Nuai
  • , Suresh Chari
  • , Ian Molloy
  • , Youngja Park
  • Purdue University
  • IBM

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Firewall policies are notorious for having misconfiguration errors which can defeat its intended purpose of protecting hosts in the network from malicious users. We believe this is because today's firewall policies are mostly monolithic. Inspired by ideas from modular programming and code refactoring, in this work we introduce three kinds of modules: primary, auxiliary, and template, which facilitate the refactoring of a firewall policy into smaller, reusable, comprehensible, and more manageable components. We present algorithms for generating each of the three modules for a given legacy firewall policy. We also develop ModFP, an automated tool for converting legacy firewall policies represented in access control list to their modularized format. With the help of ModFP, when examining several real-world policies with sizes ranging from dozens to hundreds of rules, we were able to identify subtle errors.

Original languageEnglish
Title of host publicationSACMAT 2016 - Proceedings of the 21st ACM Symposium on Access Control Models and Technologies
PublisherAssociation for Computing Machinery
Pages37-48
Number of pages12
ISBN (Electronic)9781450338028
DOIs
StatePublished - Jun 6 2016
Event21st ACM Symposium on Access Control Models and Technologies, SACMAT 2016 - Shanghai, China
Duration: Jun 6 2016Jun 8 2016

Publication series

NameProceedings of ACM Symposium on Access Control Models and Technologies, SACMAT
Volume06-08-June-2016

Conference

Conference21st ACM Symposium on Access Control Models and Technologies, SACMAT 2016
Country/TerritoryChina
CityShanghai
Period06/6/1606/8/16

Keywords

  • Firewall policies
  • Firewall tool
  • Modularization

Fingerprint

Dive into the research topics of 'Tri-modularization of firewall policies'. Together they form a unique fingerprint.

Cite this