Article
CONFIDDENT: A model-driven consistent and non-redundant layer-3 firewall ACL design, development and maintenance framework
Author/s | Pozo Hidalgo, Sergio
Martínez Gasca, Rafael Reina Quintero, Antonia María Varela Vaca, Ángel Jesús |
Department | Universidad de Sevilla. Departamento de Lenguajes y Sistemas Informáticos |
Publication Date | 2012 |
Deposit Date | 2022-11-16 |
Published in |
|
Abstract | Design, development, and maintenance of firewall ACLs are very hard and error-prone tasks. Two of the reasons for these
difficulties are, on the one hand, the big gap that exists between the access control requirements ... Design, development, and maintenance of firewall ACLs are very hard and error-prone tasks. Two of the reasons for these difficulties are, on the one hand, the big gap that exists between the access control requirements and the complex and heterogeneous firewall platforms and languages and, on the other hand, the absence of ACL design, development and maintenance environments that integrate inconsis-tency and redundancy diagnosis. The use of modelling languages surely helps but, although several ones have been proposed, none of them has been widely adopted by industry due to a combination of factors: high complexity, unsupported firewall important features, no integrated model validation stages, etc. In this paper, CONFIDDENT, a model-driven design, development and maintenance framework for layer-3 firewall ACLs is proposed. The framework includes different modelling stages at different abstraction lev-els. In this way, non-experienced administrators can use more abstract models while experienced ones can refine them to include platform-specific features. CONFIDDENT includes different model diagnosis stages where the administrators can check the inconsistencies and redundancies of their models before the automatic generation of the ACL to one of the many of the market-leader firewall platforms currently supported. |
Funding agencies | Ministerio de Educación y Ciencia (MEC). España |
Project ID. | TIN2009-13714 |
Citation | Pozo Hidalgo, S., Martínez Gasca, R., Reina Quintero, A.M. y Varela Vaca, Á.J. (2012). CONFIDDENT: A model-driven consistent and non-redundant layer-3 firewall ACL design, development and maintenance framework. Journal of Systems and Software, 85 (2), 425-457. https://doi.org/10.1016/j.jss.2011.09.008. |
Files | Size | Format | View | Description |
---|---|---|---|---|
Confiddent A model-driven ... | 3.137Mb | [PDF] | View/ | |