dc.creator | Pozo Hidalgo, Sergio | es |
dc.creator | Ceballos Guerrero, Rafael | es |
dc.creator | Martínez Gasca, Rafael | es |
dc.date.accessioned | 2022-02-16T10:52:14Z | |
dc.date.available | 2022-02-16T10:52:14Z | |
dc.date.issued | 2008 | |
dc.identifier.citation | Pozo Hidalgo, S., Ceballos Guerrero, R. y Martínez Gasca, R. (2008). A heuristic polynomial algorithm for local inconsistency diagnosis in firewall rule sets. En SECRYPT 2008: International Conference on Security and Cryptography (430-441), Porto, Portugal: SciTePress. | |
dc.identifier.isbn | 978-989-8111-59-3 | es |
dc.identifier.issn | 2184-2825 | es |
dc.identifier.uri | https://hdl.handle.net/11441/130002 | |
dc.description.abstract | Firewall ACLs can contain inconsistencies. There is an inconsistency if different actions can be taken on the
same flow of traffic, depending on the ordering of the rules. Inconsistent rules should be notified to the
system administrator in order to remove them. Minimal diagnosis and characterization of inconsistencies is
a combinatorial problem. Although many algorithms have been proposed to solve this problem, all reviewed
ones work with the full ACL with no approximate heuristics, giving minimal and complete results, but
making the problem intractable for large, real-life ACLs. In this paper we take a different approach. First,
we deeply analyze the inconsistency diagnosis in firewall ACLs problem, and propose to split the process in
several parts that can be solved sequentially: inconsistency detection, inconsistent rules identification, and
inconsistency characterization. We present polynomial heuristic algorithms for the first two parts of the
problem: detection and identification (diagnosis) of inconsistent rules. The algorithms return several
independent clusters of inconsistent rules that can be characterized against a fault taxonomy. These clusters
contains all inconsistent rules of the ACL (algorithms are complete), but the algorithms not necessarily give
the minimum number of clusters. The main advantage of the proposed heuristic diagnosis process is that
optimal characterization can be now applied to several smaller problems (the result of the diagnosis process)
rather than to the whole ACL, resulting in an effective computational complexity reduction at the cost of not
having the minimal diagnosis. Experimental results with real ACLs are given. | es |
dc.description.sponsorship | Ministerio de Educación y Ciencia DPI2006-15476-C02-01 | es |
dc.format | application/pdf | es |
dc.format.extent | 12 | es |
dc.language.iso | eng | es |
dc.publisher | SciTePress | es |
dc.relation.ispartof | SECRYPT 2008: International Conference on Security and Cryptography (2008), pp. 430-441. | |
dc.rights | Attribution-NonCommercial-NoDerivatives 4.0 Internacional | * |
dc.rights.uri | http://creativecommons.org/licenses/by-nc-nd/4.0/ | * |
dc.subject | Diagnosis | es |
dc.subject | Consistency | es |
dc.subject | Conflict | es |
dc.subject | Anomaly | es |
dc.subject | Firewall | es |
dc.subject | acl | es |
dc.subject | ruleset | es |
dc.title | A heuristic polynomial algorithm for local inconsistency diagnosis in firewall rule sets | es |
dc.type | info:eu-repo/semantics/conferenceObject | es |
dcterms.identifier | https://ror.org/03yxnpp24 | |
dc.type.version | info:eu-repo/semantics/submittedVersion | es |
dc.rights.accessRights | info:eu-repo/semantics/openAccess | es |
dc.contributor.affiliation | Universidad de Sevilla. Departamento de Lenguajes y Sistemas Informáticos | es |
dc.relation.projectID | DPI2006-15476-C02-01 | es |
dc.relation.publisherversion | https://www.scitepress.org/PublicationsDetail.aspx?ID=chdlFhXyZjA=&t=1 | es |
dc.identifier.doi | 10.5220/0001921504300441 | es |
dc.publication.initialPage | 430 | es |
dc.publication.endPage | 441 | es |
dc.eventtitle | SECRYPT 2008: International Conference on Security and Cryptography | es |
dc.eventinstitution | Porto, Portugal | es |
dc.relation.publicationplace | Setúbal, Portugal | es |
dc.contributor.funder | Ministerio de Educación y Ciencia (MEC). España | es |