Diverse firewall design

Diverse firewall design
复制标题

DOI:
10.1109/tpds.2007.70802
复制
发表时间:
2008-09-01
影响因子:
5.3
通讯作者:
Gouda, Mohamed G.
Gouda, Mohamed G.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Liu, Alex X.;Gouda, Mohamed G.

文献摘要

被引文献

相似文献

防火墙是企业安全的中流砥柱,也是用于保护私有网络的最广泛采用的技术。防火墙策略中的错误要么会造成安全漏洞,从而允许恶意流量潜入专用网络,要么会阻止合法流量并中断正常的业务流程,这反过来可能导致不可挽回的(如果不是悲惨的)后果。据观察,Internet上的大多数防火墙策略设计得很差,并且存在许多错误。因此,如何正确地设计防火墙策略是一个重要的问题。在本文中,我们提出了多样化防火墙的设计方法,该方法包括三个阶段:设计阶段、比较阶段和解决阶段。在设计阶段,将防火墙策略的相同需求规范提供给多个团队,这些团队独立进行设计防火墙策略的不同版本。在比较阶段,将产生的多个版本相互比较,以检测它们之间的所有功能差异。在解决阶段,所有差异都得到解决,并且生成了所有团队都同意的防火墙。不同防火墙设计方法中的主要技术挑战是如何发现两个给定防火墙策略之间的所有功能差异。我们提出了一系列三种有效的算法来解决这个问题:构造算法、成形算法和比较算法。用于发现两个给定防火墙策略之间所有功能差异的算法也可用于执行防火墙策略更改影响分析。随着网络的发展和新威胁的出现,防火墙策略经常需要更改。许多防火墙策略错误是由策略更改的意外副作用引起的。我们的算法可以通过计算策略变化前和策略变化后的功能差异来直接计算防火墙策略变化的影响。
Firewalls are the mainstay of enterprise security and the most widely adopted technology for protecting private networks. An error in a firewall policy either creates security holes that will allow malicious traffic to sneak into a private network or blocks legitimate traffic and disrupts normal business processes, which, in turn, could lead to irreparable, if not tragic, consequences. It has been observed that most firewall policies on the Internet are poorly designed and have many errors. Therefore, how one can design firewall policies correctly is an important issue. In this paper, we propose the method of diverse firewall design, which consists of three phases: a design phase, a comparison phase, and a resolution phase. In the design phase, the same requirement specification of a firewall policy is given to multiple teams who proceed independently to design different versions of the firewall policy. In the comparison phase, the resulting multiple versions are compared with each other to detect all functional discrepancies between them. In the resolution phase, all discrepancies are resolved, and a firewall that is agreed upon by all teams is generated. The major technical challenge in the method of diverse firewall design is how one can discover all functional discrepancies between two given firewall policies. We present a series of three efficient algorithms for solving this problem: a construction algorithm, a shaping algorithm, and a comparison algorithm. The algorithms for discovering all functional discrepancies between two given firewall policies can be used to perform firewall policy change impact analysis as well. Firewall policies often need to be changed, as networks evolve, and new threats emerge. Many firewall policy errors are caused by the unintended side effects of policy changes. Our algorithms can be used directly to compute the impact of firewall policy changes by computing the functional discrepancies between the policy before changes and the policy after changes.