Back to Search Start Over

Automatic analysis of firewall and network intrusion detection system configurations.

Authors :
Uribe, Tomás E.
Cheung, Steven
Source :
Journal of Computer Security. 2007, Vol. 15 Issue 6, p691-715. 25p.
Publication Year :
2007

Abstract

Firewalls and network intrusion detection systems (NIDSs) are widely used to secure computer networks. Given a network that deploys multiple firewalls and NIDSs, ensuring that these security components are correctly configured is a challenging problem. Although models have been developed to reason independently about the effectiveness of firewalls and NIDSs, there is no common framework to analyze their interaction. This paper presents an integrated, constraint-based approach for modeling and reasoning about these configurations. Our approach considers the dependencies among the two types of components, and can reason automatically about their combined behavior. We have developed a tool for the specification and verification of networks that include multiple firewalls and NIDSs, based on this approach. This tool can also be used to automatically generate NIDS configurations that are optimal relative to a given cost function. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
0926227X
Volume :
15
Issue :
6
Database :
Academic Search Index
Journal :
Journal of Computer Security
Publication Type :
Academic Journal
Accession number :
26619529
Full Text :
https://doi.org/10.3233/JCS-2007-15605