Sie befinden Sich nicht im Netzwerk der Universität Paderborn. Der Zugriff auf elektronische Ressourcen ist gegebenenfalls nur via VPN oder Shibboleth (DFN-AAI) möglich. mehr Informationen...
Ergebnis 20 von 71
2008 Symposium on Reliable Distributed Systems, 2008, p.105-114
2008
Volltextzugriff (PDF)

Details

Autor(en) / Beteiligte
Titel
Systematic Structural Testing of Firewall Policies
Ist Teil von
  • 2008 Symposium on Reliable Distributed Systems, 2008, p.105-114
Ort / Verlag
IEEE
Erscheinungsjahr
2008
Quelle
IEEE Xplore
Beschreibungen/Notizen
  • Firewalls are the mainstay of enterprise security and the most widely adopted technology for protecting private networks. As the quality of protection provided by a firewall directly depends on the quality of its policy (i.e., configuration), ensuring the correctness of security policies is important and yet difficult.To help ensure the correctness of a firewall policy, we propose a systematic structural testing approach for firewall policies. We define structural coverage (based on coverage criteria of rules, predicates, and clauses) on the policy under test. Considering achieving higher structural coverage effectively, we develop three automated packet generation techniques: the random packet generation, the one based on local constraint solving (considering individual rules locally in a policy), and the most sophisticated one based on global constraint solving (considering multiple rules globally in a policy).We have conducted an experiment on a set of real policies and a set of faulty policies to detect faults with generated packet sets. Generally, our experimental results show that a packet set with higher structural coverage has higher fault detection capability (i.e., detecting more injected faults). Our experimental results show that a reduced packet set (maintaining the same level of structural coverage with the corresponding original packet set) maintains similar fault detection capability with the original set.
Sprache
Englisch
Identifikatoren
ISBN: 0769534104, 9780769534107
ISSN: 1060-9857
eISSN: 2575-8462
DOI: 10.1109/SRDS.2008.34
Titel-ID: cdi_ieee_primary_4690805

Weiterführende Literatur

Empfehlungen zum selben Thema automatisch vorgeschlagen von bX