Presentation
Fast algorithms for consistency-based diagnosis of firewall rule sets
Author/s | Pozo Hidalgo, Sergio
Ceballos Guerrero, Rafael ![]() ![]() ![]() ![]() ![]() ![]() ![]() Martínez Gasca, Rafael ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Department | Universidad de Sevilla. Departamento de Lenguajes y Sistemas Informáticos |
Date | 2008 |
Published in |
|
ISBN/ISSN | 978-0-7695-3102-1 |
Abstract | Firewalls provide the first line of defence of nearly
all networked institutions today. However, Firewall
ACL management suffer some problems that need to be
addressed in order to be effective. The most studied
one is ... Firewalls provide the first line of defence of nearly all networked institutions today. However, Firewall ACL management suffer some problems that need to be addressed in order to be effective. The most studied one is rule set consistency. There is an inconsistency if different actions can be taken on the same traffic, depending on the ordering of the rules. In this paper a new algorithm to diagnose inconsistencies in firewall rule sets is presented. Although many algorithms have been proposed to address this problem, the presented one is a big improvement over them, due to its low algorithmic and memory complexity, even in worst case. In addition, there is no need to pre-process in any way the rule set previous to the application of the algorithms. We also present experimental results with real rule sets that validate our proposal. |
Funding agencies | Ministerio de Educación y Ciencia (MEC). España |
Project ID. | DPI2006-15476-C02-01
![]() |
Citation | Pozo Hidalgo, S., Ceballos Guerrero, R. y Martínez Gasca, R. (2008). Fast algorithms for consistency-based diagnosis of firewall rule sets. En ARES 2008: Third International Conference on Availability, Reliability and Security (229-236), Barcelona, España: IEEE Computer Society. |
Files | Size | Format | View | Description |
---|---|---|---|---|
ares08.pdf | 265.8Kb | ![]() | View/ | |