2015
DOI: 10.1007/978-3-319-19249-9_13
|View full text |Cite
|
Sign up to set email alerts
|

Semantics-Preserving Simplification of Real-World Firewall Rule Sets

Abstract: The security provided by a firewall for a computer network almost completely depends on the rules it enforces. For over a decade, it has been a well-known and unsolved problem that the quality of many firewall rule sets is insufficient. Therefore, there are many tools to analyze them. However, we found that none of the available tools could handle typical, real-world iptables rulesets. This is due to the complex chain model used by iptables, but also to the vast amount of possible match conditions that occur i… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
11
0

Year Published

2015
2015
2019
2019

Publication Types

Select...
4
1
1

Relationship

4
2

Authors

Journals

citations
Cited by 6 publications
(11 citation statements)
references
References 14 publications
0
11
0
Order By: Relevance
“…NetKAT [43]; VeriFlow [49]; FML [50] Firmato [38]; FLIP [3]; NetKAT [43]; Mignis [51]; Or-BAC [52]; topoS step C+D HSA [53]; Anteater [54]; Config-Checker [55] Fireman [2]; HSA [53]; Anteater [54]; ConfigChecker [55]; VeriFlow [49] Fireman [2]; ITVal [56]; fffuu Iptables Semantics [19] translates maps verifies Fig. 17.…”
Section: Box Semanticsmentioning
confidence: 99%
See 2 more Smart Citations
“…NetKAT [43]; VeriFlow [49]; FML [50] Firmato [38]; FLIP [3]; NetKAT [43]; Mignis [51]; Or-BAC [52]; topoS step C+D HSA [53]; Anteater [54]; Config-Checker [55] Fireman [2]; HSA [53]; Anteater [54]; ConfigChecker [55]; VeriFlow [49] Fireman [2]; ITVal [56]; fffuu Iptables Semantics [19] translates maps verifies Fig. 17.…”
Section: Box Semanticsmentioning
confidence: 99%
“…Horizontal Enhancements: Most analysis tools make simplifying assumptions about the underlying network boxes. Diekmann et al [19] present simplification of iptables firewalls. This makes complex real-world firewalls available for tools which were built with simplifying assumptions about rulesets.…”
Section: Box Semanticsmentioning
confidence: 99%
See 1 more Smart Citation
“…Those express the connectivity between Network Components. The latter can be represented as raw dumps (Firewall Raw ) or in a simplified format (Firewall Rule) to ease transformation between different firewall applications as proposed in [10]. As a simplification is not free of information loss, the raw information is stored additionally.…”
Section: Description Of the Information Modelmentioning
confidence: 99%
“…Nor are the tools themselves formally verified, which limits confidence in their results. In addition, the tools only support a limited subset of real-world firewalls [19]. If the firewall under analysis exceeds this feature set, the tools either produce erroneous results or cannot continue [19].…”
Section: Related Workmentioning
confidence: 99%