Using Argumentation Logic for Firewall Policy Specification and Analysis

Using Argumentation Logic for Firewall Policy Specification and Analysis
复制标题

使用论证逻辑进行防火墙策略规范和分析

DOI:
10.1007/11907466_16
复制
发表时间:
2006
影响因子:
--
通讯作者:
A. Russo
A. Russo
中科院分区:
--
文献类型:
--
作者:
A. Bandara;A. Kakas;Emil C. Lupu;A. Russo

文献摘要

被引文献

相似文献

防火墙是重要的外围安全机制,可实现组织的网络安全需求,并且很难正确配置。鉴于它们的广泛使用,网络管理员必须拥有将其安全需求转换为防火墙配置规则的工具,并确保这些规则彼此一致。在本文中,我们提出了一种防火墙策略规范和分析的方法,该方法使用基于论证的偏好推理的正式框架。通过允许管理员定义网络抽象(如子网、协议等),安全需求可以使用高级术语以声明的方式指定。也可以指定偏好来表达一个需求比另一个需求重要。使用正式框架意味着可以自动分析所定义的安全需求的不一致性,并且可以自动生成防火墙配置。我们证明,该技术允许指定和自动检查任何不一致属性,包括在以前的研究中确定的那些属性,并且使用论证推理框架为管理员提供有关不一致原因的信息。
Firewalls are important perimeter security mechanisms that imple-ment an organisation's network security requirements and can be notoriously difficult to configure correctly. Given their widespread use, it is crucial that network administrators have tools to translate their security requirements into firewall configuration rules and ensure that these rules are consistent with each other. In this paper we propose an approach to firewall policy specification and analysis that uses a formal framework for argumentation based preference reasoning. By allowing administrators to define network abstractions (e.g. subnets, protocols etc) security requirements can be specified in a declarative manner using high-level terms. Also it is possible to specify preferences to express the importance of one requirement over another. The use of a formal framework means that the security requirements defined can be automatically analysed for inconsistencies and firewall configurations can be automatically generated. We demonstrate that the technique allows any inconsistency property, including those identified in previous research, to be specified and automatically checked and the use of an argumentation reasoning framework provides administrators with information regarding the causes of the inconsistency.