Automatic analysis of firewall and network intrusion detection system configurations

被引:7
|
作者
Uribe, Tomas [1 ]
Cheung, Steven [1 ]
机构
[1] SRI Int, Comp Sci Lab, 333 Ravenswood Ave, Menlo Pk, CA 94025 USA
关键词
Formal specification and analysis; network intrusion detection; firewalls; network configuration and security;
D O I
10.3233/JCS-2007-15605
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls and network intrusion detection systems (NIDSs) are widely used to secure computer networks. Given a network that deploys multiple firewalls and NIDSs, ensuring that these security components are correctly configured is a challenging problem. Although models have been developed to reason independently about the effectiveness of firewalls and NIDSs, there is no common framework to analyze their interaction. This paper presents an integrated, constraint-based approach for modeling and reasoning about these configurations. Our approach considers the dependencies among the two types of components, and can reason automatically about their combined behavior. We have developed a tool for the specification and verification of networks that include multiple firewalls and NIDSs, based on this approach. This tool can also be used to automatically generate NIDS configurations that are optimal relative to a given cost function.
引用
收藏
页码:691 / 715
页数:25
相关论文
共 50 条
  • [41] Automatic optimization of height network configurations for detection of surface deformations
    Holst, Christoph
    Eling, Christian
    Kuhlmann, Heiner
    JOURNAL OF APPLIED GEODESY, 2013, 7 (02) : 103 - 113
  • [42] Analysis of the Capability and Training of Chat Bots in the Generation of Rules for Firewall or Intrusion Detection Systems
    Louro, Bernardo
    Abreu, Raquel
    Costa, Joana C.
    Sequeiros, Joao B. F.
    Inacio, Pedro R. M.
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [43] Performance of network intrusion detection cluster system
    Watanabe, K
    Tsuruoka, N
    Himeno, R
    HIGH PERFORMANCE COMPUTING, 2003, 2858 : 278 - 287
  • [44] Ensemble Classifiers for Network Intrusion Detection System
    Zainal, Anazida
    Maarof, Mohd Aizaini
    Shamsuddin, Siti Mariyam
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2009, 4 (03): : 217 - 225
  • [45] Research on Computer Network Intrusion Detection System
    Sun, Bo
    PROCEEDINGS OF THE 2017 4TH INTERNATIONAL CONFERENCE ON MACHINERY, MATERIALS AND COMPUTER (MACMC 2017), 2017, 150 : 27 - 30
  • [46] Network Intrusion Detection System in a Light Bulb
    Manocchio, Liam Daly
    Layeghy, Siamak
    Portmann, Marius
    2022 32ND INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2022, : 359 - 366
  • [47] Research on the System Model of Network Intrusion Detection
    Yang Yunfeng
    PROCEEDINGS OF THE 2012 INTERNATIONAL CONFERENCE OF MODERN COMPUTER SCIENCE AND APPLICATIONS, 2013, 191 : 185 - 190
  • [48] Forest intrusion detection system with sensor network
    Koszteczky, Bence
    Vakulya, Gergely
    Simon, Gyula
    2015 IEEE INTERNATIONAL INSTRUMENTATION AND MEASUREMENT TECHNOLOGY CONFERENCE (I2MTC), 2015, : 1672 - 1676
  • [49] An Efficient Network Intrusion Detection and Classification System
    Ahmad, Iftikhar
    Ul Haq, Qazi Emad
    Imran, Muhammad
    Alassafi, Madini O.
    AlGhamdi, Rayed A.
    MATHEMATICS, 2022, 10 (03)
  • [50] An Efficient Cloud Network Intrusion Detection System
    Ghosh, Partha
    Mandal, Abhay Kumar
    Kumar, Rupesh
    INFORMATION SYSTEMS DESIGN AND INTELLIGENT APPLICATIONS, VOL 1, 2015, 339 : 91 - 99