|
ABSTRACT
In recent years packet-filtering firewalls have seen some impressive technological advances (e.g., stateful inspection, transparency, performance, etc.) and wide-spread deployment. In contrast, firewall and security <i>management</i> technology is lacking. In this paper we present <i>Firmato</i>, a firewall management toolkit, with the following distinguishing properties and components: (1) an entity-relationship model containing, in a unified form, global knowledge of the security policy and of the network topology; (2) a model definition language, which we use as an interface to define an instance of the entity-relationship model; (3) a model compiler, translating the global knowledge of the model into firewall-specific configuration files; and (4) a graphical firewall rule illustrator. We implemented a prototype of our toolkit to work with several commercially available firewall products. This prototype was used to control an operational firewall for several months. We believe that our approach is an important step toward streamlining the process of configuring and managing firewalls, especially in complex, multi-firewall installations.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Ravindra K. Ahuja , Thomas L. Magnanti , James B. Orlin, Network flows: theory, algorithms, and applications, Prentice-Hall, Inc., Upper Saddle River, NJ, 1993
|
| |
2
|
Bartal, Y., Mayer, A., Nissim, K., and Wool, A. 1999. Firmato: A novel firewall management toolkit. In Proceedings of the 20th IEEE Symp. on Security and Privacy. IEEE, Oakland, CA. 17--31.
|
| |
3
|
Bellovin, S. M. 1999. Distributed firewalls. ;login: The Magazine of USENIX & SAGE. 39--47.
|
| |
4
|
Carney, M. and Loe, B. 1998. A comparison of methods for implementing adaptive security policies. In Proceedings of the 7th USENIX Security Symposium. Usenix Association, Berkeley. 1--14.
|
| |
5
|
|
| |
6
|
|
| |
7
|
|
| |
8
|
Dot. 2001. Graphviz---open source graph drawing software. version 1.7. http://www.research.att.com/sw/tools/graphviz/.
|
| |
9
|
FWB 2002. Firewall builder. http://www.fwbuilder.org.
|
| |
10
|
|
| |
11
|
|
| |
12
|
|
| |
13
|
|
| |
14
|
|
| |
15
|
Held, G. and Hundley, K. 1999. Cisco Access Lists. McGraw-Hill.
|
| |
16
|
|
| |
17
|
HLFL 2002. HLFL---high level firewall language. http://www.hlfl.org.
|
| |
18
|
Howe, C. D., Erwin, B., Barth, C., and Elliot, S. 1996. What's beyond firewalls? The Forrester Report 10, 12 (Nov.).
|
| |
19
|
ICSA Labs. 2003. Certified firewall products. http://www.icsalabs.com/html/communities/firewalls/certification/rxvendors/index.shtml.
|
 |
20
|
Sotiris Ioannidis , Angelos D. Keromytis , Steve M. Bellovin , Jonathan M. Smith, Implementing a distributed firewall, Proceedings of the 7th ACM conference on Computer and communications security, p.190-199, November 01-04, 2000, Athens, Greece
[doi> 10.1145/352600.353052]
|
 |
21
|
|
| |
22
|
Limoncelli, T. A. 1999. Tricks you can do if your firewall is a bridge. In First USENIX Conference on Network Administration (NETA). USENIX, Santa Clara, CA.
|
| |
23
|
Lucent 2002. Lucent VPN firewall brick. http://www.lucent.com/security.
|
| |
24
|
|
| |
25
|
Reed, D. 2002. Filter language compiler. http://cheops.anu.edu.au/ avalon/flc.html.
|
| |
26
|
|
| |
27
|
Sandhu, R. S. 1998. Role-based access control. In Advances in Computers, M. Zerkowitz, Ed. Vol. 48. Academic Press.
|
| |
28
|
Solsoft. 2000. Solsoft NP: Putting security policies into practice. Enterprise Management Associates white paper. http://www.solsoft.com/library/ema_profiler.pdf.
|
 |
29
|
Michael M. Swift , Anne Hopkins , Peter Brundrett , Cliff Van Dyke , Praerit Garg , Shannon Chan , Mario Goertzel , Gregory Jensenworth, Improving the granularity of access control for Windows 2000, ACM Transactions on Information and System Security (TISSEC), v.5 n.4, p.398-437, November 2002
[doi> 10.1145/581271.581273]
|
| |
30
|
|
| |
31
|
Wool, A. 2001. Architecting the Lumeta firewall analyzer. In 10th USENIX Security Symposium. USENIX, Washington, D.C. 85--97.
|
| |
32
|
Wool, A. 2004a. The use and usability of direction-based filtering in firewalls. Computers & Security 23, 6, 459--468.
|
| |
33
|
|
CITED BY 3
|
|
|
|
|
Venanzio Capretta , Bernard Stepien , Amy Felty , Stan Matwin, Formal correctness of conflict detection for firewalls, Proceedings of the 2007 ACM workshop on Formal methods in security engineering, p.22-30, November 02-02, 2007, Fairfax, Virginia, USA
|
|
|
|
REVIEW
"Anthony Donald Vanker : Reviewer"
A prototype firewall management toolkit is discussed in this paper. The authors wanted a tool that was firewall vendor independent, separated security policy from network topology, generated firewall configurations (as rules) automatically, and pr
more...
|