Using argumentation logic for firewall configuration management

Using argumentation logic for firewall configuration management
复制标题

使用论证逻辑进行防火墙配置管理

DOI:
--
复制
发表时间:
2009
期刊:
2009 IFIP/IEEE International Symposium on Integrated Network Management
影响因子:
--
通讯作者:
A. Russo
A. Russo
中科院分区:
--
文献类型:
--
作者:
A. Bandara;A. Kakas;Emil C. Lupu;A. Russo

文献摘要

被引文献

相似文献

防火墙仍然是企业网络的主要外围安全保护。然而,网络的规模和复杂性使得防火墙的配置和维护非常困难。需要工具来分析防火墙配置的错误,以验证它们是否正确地实现了安全要求,并根据更高级别的要求生成配置。在本文中,我们扩展了我们以前的工作,使用正式的论证和偏好推理的防火墙政策分析和开发手段,自动生成防火墙的政策,从更高层次的要求。这使得分析和生成都可以在同一个框架内完成,从而适应了创作和维护防火墙配置的各种场景。我们验证我们的方法,将其应用到文献和真实的防火墙配置的中等大小(150规则)的例子。
Firewalls remain the main perimeter security protection for corporate networks. However, network size and complexity make firewall configuration and maintenance notoriously difficult. Tools are needed to analyse firewall configurations for errors, to verify that they correctly implement security requirements and to generate configurations from higher-level requirements. In this paper we extend our previous work on the use of formal argumentation and preference reasoning for firewall policy analysis and develop means to automatically generate firewall policies from higher-level requirements. This permits both analysis and generation to be done within the same framework, thus accommodating a wide variety of scenarios for authoring and maintaining firewall configurations. We validate our approach by applying it to both examples from the literature and real firewall configurations of moderate size (≈ 150 rules).