2019/12/16 by Frédéric Cuppens, Cuppens, Frédéric, Nora Cuppens-Boulahia +4
Computer Science · Mathematics · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #FOS: Mathematics #Internet Traffic Analysis and Secure E-voting #Logic (math.LO) #Network Packet Processing and Optimization #Network Security and Intrusion Detection #cs.CR #math.LO
paper · pdf · doi:10.48550/arxiv.1912.07283
9 pages, 4 figures, 10 references, 7th International Symposium on System and Information Security (SSI), Sao Paulo, Brazil
arxiv created 2019/12/16 · openalex publication_date 2019/12/16 · arxiv updated 2019/12/17 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Many companies and organizations use firewalls to control the access to their network infrastructure. Firewalls are network security components which provide means to filter traffic within corporate networks, as well as to police incoming and outcoming interaction with the Internet. For this purpose, it is necessary to configure firewalls with a set of filtering rules. Nevertheless, the existence of errors in a set of filtering rules is very likely to degrade the network security policy. The discovering and removal of these configuration errors is a serious and complex problem to solve. In this paper, we present a set of algorithms for such a management. Our approach is based on the analysis of relationships between the set of filtering rules. Then, a subsequent rewriting of rules will derive from an initial firewall setup -- potentially misconfigured -- to an equivalent one completely free of errors. At the same time, the algorithms will detect useless rules in the initial firewall configuration.