Mostrar el registro sencillo del ítem

Artículo

dc.creatorPozo Hidalgo, Sergioes
dc.creatorCeballos Guerrero, Rafaeles
dc.creatorMartínez Gasca, Rafaeles
dc.date.accessioned2022-02-15T12:04:39Z
dc.date.available2022-02-15T12:04:39Z
dc.date.issued2009
dc.identifier.citationPozo Hidalgo, S., Ceballos Guerrero, R. y Martínez Gasca, R. (2009). Model-Based Development of firewall rule sets: Diagnosing model inconsistencies. Information and Software Technology, 51 (5), 894-915.
dc.identifier.issn0950-5849es
dc.identifier.urihttps://hdl.handle.net/11441/129978
dc.description.abstractThe design and management of firewall rule sets is a very difficult and error-prone task because of the difficulty of translating access control requirements into complex low-level firewall languages. Although high-level languages have been proposed to model firewall access control lists, none has been widely adopted by the industry. We think that the main reason is that their complexity is close to that of many existing low-level languages. In addition, none of the high-level languages that automatically generate firewall rule sets verifies the model prior to the code-generation phase. Error correction in the early stages of the development process is cheaper compared to the cost associated with correcting errors in the production phase. In addition, errors generated in the production phase usually have a huge impact on the reliability and robustness of the generated code and final system. In this paper, we propose the application of the ideas of Model-Based Development to firewall access control list modelling and automatic rule set generation. First, an analysis of the most widely used firewall languages in the industry is conducted. Next, a Platform-Independent Model for firewall ACLs is proposed. This model is the result of exhaustive analysis and of a discussion of different alternatives for models in a bottom-up methodology. Then, it is proposed that a verification stage be added in the early stages of the Model-Based Development methodology, and a polynomial time complexity process and algorithms are proposed to detect and diagnose inconsistencies in the Platform-Independent Model. Finally, a theoretical complexity analysis and empirical tests with real models were conducted, in order to prove the feasibility of our proposal in real environments.es
dc.formatapplication/pdfes
dc.format.extent22es
dc.language.isoenges
dc.publisherElsevieres
dc.relation.ispartofInformation and Software Technology, 51 (5), 894-915.
dc.rightsAttribution-NonCommercial-NoDerivatives 4.0 Internacional*
dc.rights.urihttp://creativecommons.org/licenses/by-nc-nd/4.0/*
dc.subjectMBEes
dc.subjectFirewallses
dc.subjectConsistencyes
dc.subjectValidationes
dc.subjectModeles
dc.titleModel-Based Development of firewall rule sets: Diagnosing model inconsistencieses
dc.typeinfo:eu-repo/semantics/articlees
dc.type.versioninfo:eu-repo/semantics/publishedVersiones
dc.rights.accessRightsinfo:eu-repo/semantics/openAccesses
dc.contributor.affiliationUniversidad de Sevilla. Departamento de Lenguajes y Sistemas Informáticoses
dc.relation.publisherversionhttps://www.sciencedirect.com/science/article/pii/S0950584908000785?via%3Dihubes
dc.identifier.doi10.1016/j.infsof.2008.05.001es
dc.journaltitleInformation and Software Technologyes
dc.publication.volumen51es
dc.publication.issue5es
dc.publication.initialPage894es
dc.publication.endPage915es
dc.identifier.sisius6717333es

FicherosTamañoFormatoVerDescripción
Model-based development of ...1.789MbIcon   [PDF] Ver/Abrir  

Este registro aparece en las siguientes colecciones

Mostrar el registro sencillo del ítem

Attribution-NonCommercial-NoDerivatives 4.0 Internacional
Excepto si se señala otra cosa, la licencia del ítem se describe como: Attribution-NonCommercial-NoDerivatives 4.0 Internacional