BISCAL: bit vector based spatial calculus for analyzing the mis-configurations in firewall policies (インターネットアーキテクチャ)
スポンサーリンク
概要
- 論文の詳細を見る
Packet filtering in firewalls operates at the network level of the OSI model, or the IP layer of TCP/IP. In a packet filtering each packet is compared to a set of conditions before it is forwarded. Depending on the header of the packet, the firewall accepts or denies the packet. Since business needs are dynamic, firewall policies are constantly being changed and modified. Firewall administration teams in large organizations often process dozens of filter additions and changes daily. This continuous flux causes the firewall configuration to grow dramatically over time. A huge and, subsequently complex, firewall configuration is hard to manage and may require lengthy research in order to add or change a filter and results in mis-configurations in firewall policies. Powerful error classification method was proposed based upon the geometrical interpretation of policies in order to detect such mis-configurations in firewall policies. However, as the filters and key fields of the header increase, it demands high memory and computation time. We propose a topological approach called BISCAL (Bit-vector based spatial calculus) to detect the conflicts in the firewall policies to solve this problem.
- 社団法人電子情報通信学会の論文
- 2009-01-21
著者
-
Thanasegaran Subana
Graduate School of Engineering, Nagoya Institute of Technology
-
Thanasegaran Subana
Graduate School Of Engineering Nagoya Institute Of Technology
-
Yin Yi
Graduate School of Engineering, Nagoya Institute of Technology
-
Tateiwa Yuichiro
Graduate School of Engineering, Nagoya Institute of Technology
-
Katayama Yoshiaki
Graduate School of Engineering, Nagoya Institute of Technology
-
Takahashi Naohisa
Graduate School of Engineering, Nagoya Institute of Technology
-
Katayama Yoshiaki
Graduate School Of Engineering Nagoya Institute Of Technology
-
Katayama Yoshiaki
Graduate School Of Computer Science And Engineering Nagoya Institute Of Technology
-
Yin Yi
Graduate School Of Engineering Nagoya Institute Of Technology
-
Tateiwa Yuichiro
Graduate School Of Engineering Nagoya Institute Of Technology
-
Takahashi Naohisa
Graduate School Of Engineering Nagoya Institute Of Technology
関連論文
- A-7-13 Detection of Conflicts in Time-Dependent Firewall Policies
- BISCAL: bit vector based spatial calculus for analyzing the mis-configurations in firewall policies (インターネットアーキテクチャ)
- Detection of Anomalies in Packet Filter Configurations
- Detection of Anomalies in Packet Filter Configurations(サービス管理・ビジネス管理,料金管理,及び一般)
- Hierarchical Composition of Self-Stabilizing Protocols Preserving the Fault-Containment Property