Automatic analysis of firewall and network intrusion detection system configurations

被引:7
|
作者
Uribe, Tomas [1 ]
Cheung, Steven [1 ]
机构
[1] SRI Int, Comp Sci Lab, 333 Ravenswood Ave, Menlo Pk, CA 94025 USA
关键词
Formal specification and analysis; network intrusion detection; firewalls; network configuration and security;
D O I
10.3233/JCS-2007-15605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls and network intrusion detection systems (NIDSs) are widely used to secure computer networks. Given a network that deploys multiple firewalls and NIDSs, ensuring that these security components are correctly configured is a challenging problem. Although models have been developed to reason independently about the effectiveness of firewalls and NIDSs, there is no common framework to analyze their interaction. This paper presents an integrated, constraint-based approach for modeling and reasoning about these configurations. Our approach considers the dependencies among the two types of components, and can reason automatically about their combined behavior. We have developed a tool for the specification and verification of networks that include multiple firewalls and NIDSs, based on this approach. This tool can also be used to automatically generate NIDS configurations that are optimal relative to a given cost function.
引用
收藏
页码:691 / 715
页数:25
相关论文
共 50 条
  • [1] Analysis on the Application of Campus Network Firewall And Intrusion Detection System
    Wang, Jinying
    Yan, Pengfei
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS RESEARCH AND MECHATRONICS ENGINEERING, 2015, 121 : 398 - 401
  • [2] Intrusion Detection System based on Software Defined Network Firewall
    Sayeed, Mohd Abuzar
    Sayeed, Mohd Asim
    Saxena, Sharad
    2015 1ST INTERNATIONAL CONFERENCE ON NEXT GENERATION COMPUTING TECHNOLOGIES (NGCT), 2015, : 379 - 382
  • [3] Distributed Firewall with Intrusion Detection System
    Xie, Linquan
    Yu, Fei
    Xu, Chen
    JOURNAL OF COMPUTERS, 2012, 7 (12) : 3110 - 3115
  • [4] AN EVOLUTIONARY GAME ANALYSIS OF THE INTERACTION WITH FIREWALL AND INTRUSION DETECTION SYSTEM
    Yin, Ying
    Xia, Zi-Chao
    PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-6, 2009, : 2787 - +
  • [5] Firewall-based intrusion detection system
    Li, X.
    Zhao, H.
    Ma, S.
    2001, Northeastern University (22):
  • [6] A mechanism of intrusion detection system cooperating with firewall
    Cao, Zijian
    Rong, Xiaofeng
    Cao, Z., 2013, Asian Network for Scientific Information (12) : 6449 - 6454
  • [7] A distributed network security architecture integrating embedded firewall and intrusion detection system
    Gao, Fuxiang
    Liang, Dagong
    Bai, Xiang
    Shang, Min
    2005 International Symposium on Computer Science and Technology, Proceedings, 2005, : 613 - 616
  • [8] Automatic backdoor analysis with a network intrusion detection system and an integrated service checker
    Juslin, J
    Virtanen, T
    IEEE SYSTEMS, MAN AND CYBERNETICS SOCIETY INFORMATION ASSURANCE WORKSHOP, 2003, : 122 - 126
  • [9] A Statefull Firewall and Intrusion Detection System Enforced with Secure Logging for Controller Area Network
    Lenard, Teri
    Bolboaca, Roland
    PROCEEDINGS OF THE 2021 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2021, 2021, : 39 - 45
  • [10] System design based on the combination of firewall and intrusion detection technology
    2005, Wuhan University of Technology, Wuhan, China (27):