作者
Lihua Yuan, Jianning Mai, Zhendong Su, Hao Chen, Chen-Nee Chuah, Prasant Mohapatra
发表日期
2006/5/21
研讨会论文
Security and Privacy, 2006 IEEE Symposium on
页码范围
15 pp.-213
出版商
IEEE
简介
Security concerns are becoming increasingly critical in networked systems. Firewalls provide important defense for network security. However, misconfigurations in firewalls are very common and significantly weaken the desired security. This paper introduces FIREMAN, a static analysis toolkit for firewall modeling and analysis. By treating firewall configurations as specialized programs, FIREMAN applies static analysis techniques to check misconfigurations, such as policy violations, inconsistencies, and inefficiencies, in individual firewalls as well as among distributed firewalls. FIREMAN performs symbolic model checking of the firewall configurations for all possible IP packets and along all possible data paths. It is both sound and complete because of the finite state nature of firewall configurations. FIREMAN is implemented by modeling firewall rules using binary decision diagrams (BDDs), which have been used …
引用总数
2006200720082009201020112012201320142015201620172018201920202021202220232024614414849595042444366372831211719174
学术搜索中的文章
L Yuan, H Chen, J Mai, CN Chuah, Z Su, P Mohapatra - 2006 IEEE Symposium on Security and Privacy (S&P' …, 2006