Tri-Modularization of Firewall Policies
Title | Tri-Modularization of Firewall Policies |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Haining Chen, Omar Chowdhury, Ninghui Li, Warut Khern-Am-Nuai, Suresh Chari, Ian Molloy, Youngja Park |
Conference Name | ACM Symposium on Access Control Models and Technologies (SACMAT) |
Date Published | 06/2016 |
Conference Location | Shanghai, China |
Keywords | Apr'16, NCSU, Policy-Governed Secure Collaboration, Scientific Understanding of Policy Complexity |
Abstract | Firewall policies are notorious for having misconfiguration errors which can defeat its intended purpose of protecting hosts in the network from malicious users. We believe this is because today's firewall policies are mostly monolithic. Inspired by ideas from modular programming and code refactoring, in this work we introduce three kinds of modules: primary, auxiliary, and template, which facilitate the refactoring of a firewall policy into smaller, reusable, comprehensible, and more manageable components. We present algorithms for generating each of the three modules for a given legacy firewall policy. We also develop ModFP, an automated tool for converting legacy firewall policies represented in access control list to their modularized format. With the help of ModFP, when examining several real-world policies with sizes ranging from dozens to hundreds of rules, we were able to identify subtle errors.
|
URL | https://dl.acm.org/citation.cfm?id=2914642.2914646 |
DOI | 10.1145/2914642.2914646 |
Citation Key | node-25874 |
Refereed Designation | Unknown |