Firewalls and Security Gateways are core elements in network security infrastructure. As networks and services become more complex, managing access-list rules becomes an error-prone task. Conflicts in a policy can cause holes in security, and can often be hard to find while performing only visual or manual inspection. First, we have defined a methodology to systematically classify the severity of rule conflicts; secondly, we have proposed two different solutions to automatically resolve conflicts in a firewall. For one of them we found an algebraic proof of the existence of the solution and the convergence of the algorithm, and then we have made a software implementation to test it. © 2007 IEEE.

Automatic conflict analysis and resolution of traffic filtering policy for firewall and Security Gateway / FERRARESI, SIMONE; S., Pesic; L., Trazza; BAIOCCHI, Andrea. - (2007), pp. 1304-1310. (Intervento presentato al convegno IEEE International Conference on Communications (ICC 2007) tenutosi a Glasgow; United Kingdom nel JUN 24-28, 2007) [10.1109/icc.2007.220].

Automatic conflict analysis and resolution of traffic filtering policy for firewall and Security Gateway

FERRARESI, SIMONE;BAIOCCHI, Andrea
2007

Abstract

Firewalls and Security Gateways are core elements in network security infrastructure. As networks and services become more complex, managing access-list rules becomes an error-prone task. Conflicts in a policy can cause holes in security, and can often be hard to find while performing only visual or manual inspection. First, we have defined a methodology to systematically classify the severity of rule conflicts; secondly, we have proposed two different solutions to automatically resolve conflicts in a firewall. For one of them we found an algebraic proof of the existence of the solution and the convergence of the algorithm, and then we have made a software implementation to test it. © 2007 IEEE.
2007
IEEE International Conference on Communications (ICC 2007)
algorithms; computer software; gateways (computer networks); network security; telecommunication traffic
Pubblicazione in atti di convegno::04b Atto di convegno in volume
Automatic conflict analysis and resolution of traffic filtering policy for firewall and Security Gateway / FERRARESI, SIMONE; S., Pesic; L., Trazza; BAIOCCHI, Andrea. - (2007), pp. 1304-1310. (Intervento presentato al convegno IEEE International Conference on Communications (ICC 2007) tenutosi a Glasgow; United Kingdom nel JUN 24-28, 2007) [10.1109/icc.2007.220].
File allegati a questo prodotto
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/357917
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 17
  • ???jsp.display-item.citation.isi??? 8
social impact