首页> 外文会议>Second IEEE International Conference on Social Computing >Automatic Conformance Verification of Distributed Firewalls to Security Requirements
【24h】

Automatic Conformance Verification of Distributed Firewalls to Security Requirements

机译:分布式防火墙自动符合性验证以达到安全要求

获取原文

摘要

Distributed firewalls are often deployed by large enterprises to filter the network traffic. However, it has been observed that the resulting complex firewall network is highly error prone and causes serious security holes. Hence, automated solutions are needed in order to check its correctness. In this paper, we propose a formal and automatic method for checking whether distributed firewalls react correctly with respect to a security policy given in a high level declarative language. When errors are detected, some useful feedback is returned to the user in order to correct the firewall configurations. Furthermore, the procedure verifies that no conflicts exist within the security policy. We show that our method is both correct and complete. Finally, it has been implemented in a prototype of verifier based on a satisfiability solver modulo theories (SMT). Experiment conducted on relevant case studies demonstrate the efficiency of our approach.
机译:大型企业通常会部署分布式防火墙以过滤网络流量。但是,已经观察到,由此产生的复杂防火墙网络极易出错,并会导致严重的安全漏洞。因此,需要自动化解决方案以检查其正确性。在本文中,我们提出了一种形式化的自动方法,用于检查分布式防火墙相对于高级声明性语言给出的安全策略是否正确反应。当检测到错误时,一些有用的反馈将返回给用户,以更正防火墙配置。此外,该过程将验证安全策略内是否不存在冲突。我们证明我们的方法既正确又完整。最后,它已在基于可满足性求解器模理论(SMT)的验证器原型中实现。在相关案例研究中进行的实验证明了我们方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号