A Conflict Detection Method for IPv6 Time-Based Firewall Policy

被引:2
|
作者
Zhang, Xue [1 ]
Yin, Yi [1 ]
Liu, Wei [1 ]
Peng, Zhizhen [1 ]
Zhang, Guoqiang [1 ]
Wang, Yun [2 ]
Tateiwa, Yuichiro [3 ]
Takahashi, Naohisa [3 ]
机构
[1] Nanjing Normal Univ, Sch Comp Sci & Technol, Nanjing, Peoples R China
[2] Southeast Univ, Sch Comp Sci & Engn, Nanjing, Peoples R China
[3] Nagoya Inst Technol, Dept Comp Sci & Engn, Nagoya, Aichi, Japan
基金
中国国家自然科学基金;
关键词
firewall policy; time-based; IPv6; SMT Solver;
D O I
10.1109/ISPA-BDCloud-SustainCom-SocialCom48970.2019.00069
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls have been a very important secure tool to protect networks against attacks, which usually filter the unauthorized traffic entering the secured network. The packet filleting based on a predefined collection of ordered rules. Along with the IPv6 protocol is widely used, and the security issues comes with it. Firewall for IPv6 network, as an important element to protect network security, it will be not able to filter packets correctly if there are conflicts that caused by the same packet matching two or more rules. In addition, a new kind of firewall with time constraint is used more and more widely by different firewall company, such as, ACLs of Cisco, Iptalbes of Linux, and the like. It is a hard work to manage the rules in IPv4 firewall policy, not to mention the rules in IPv6 time-based firewall policy. Many methods have been proposed to analyze and detect the conflicts of individual or distributed firewall policies. However, very few of them can deal with the time constraint of rules. Therefore, it is an urgent problem to detect the conflicts of the IPv6 time-based firewall policy. In order to solve this problem, we describe a method, which can analyze the IPv6 time-based firewall policy. We use a formal method to analyze the me: ' g of IPv6 time-based firewall policy. Next, we take the formal validation tool (SNIT solver 13) to detect all the possible conflicts between every two rules. Lastly, we developed an experimental system to evaluate the performance of our method.
引用
收藏
页码:435 / 442
页数:8
相关论文
共 50 条
  • [1] NSIS-based Firewall Detection in Mobile IPv6
    Li Xin
    ICN 2008: SEVENTH INTERNATIONAL CONFERENCE ON NETWORKING, PROCEEDINGS, 2008, : 698 - 702
  • [2] Firewall system based on IPv4/IPv6
    Min, LY
    Chen, J
    DCABES 2004, Proceedings, Vols, 1 and 2, 2004, : 1063 - 1065
  • [3] IPv6 Firewall Design
    Lutz, Federico H.
    Bilbao, Javier I.
    Albaca Paravan, Carlos
    Saade, Sergio D.
    Anzorena Ostengo, Agustin
    Ruiz, Ana P.
    2018 IEEE BIENNIAL CONGRESS OF ARGENTINA (ARGENCON), 2018,
  • [4] The research and application of an IPv6 firewall based on Netfilter
    Huang, Chengquan
    MECHATRONICS AND INDUSTRIAL INFORMATICS, PTS 1-4, 2013, 321-324 : 2684 - 2687
  • [5] IPv6 Firewall Functions Analysis
    Horalek, Josef
    Sobeslav, Vladimir
    COMPUTATIONAL COLLECTIVE INTELLIGENCE, ICCCI 2016, PT II, 2016, 9876 : 219 - 228
  • [6] Design and Implementation of Distributed Intelligent Firewall based on IPv6
    Ma, Qian
    Lai, Yingxu
    Jiang, Guangzhi
    2009 9TH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND APPLICATIONS, 2009, : 703 - 707
  • [7] Inconsistency Analysis of Time-Based Security Policy and Firewall Policy
    Yin, Yi
    Tateiwa, Yuichiro
    Wang, Yun
    Katayama, Yoshiaki
    Takahashi, Naohisa
    FORMAL METHODS AND SOFTWARE ENGINEERING, ICFEM 2017, 2017, 10610 : 447 - 463
  • [8] A Mapping Mechanism for Periodic Filters in a Conflict Detection System for Time-Based Firewall Policies
    Thanasegaran, Subana
    Tateiwa, Yuichiro
    Katayama, Yoshiaki
    Takahashi, Naohisa
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (02): : 112 - 119
  • [9] A Mapping Mechanism for Periodic Filters in a Conflict Detection System for Time-Based Firewall Policies
    Thanasegaran, Subana
    Tateiwa, Yuichiro
    Katayama, Yoshiaki
    Takahashi, Naohisa
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2012, 12 (04): : 29 - 36
  • [10] A Mapping Mechanism for Periodic Filters in a Conflict Detection System for Time-Based Firewall Policies
    Thanasegaran, Subana
    Tateiwa, Yuichiro
    Katayama, Yoshiaki
    Takahashi, Naohisa
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2012, 12 (03): : 108 - 115