loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: S. Pozo ; R. M. Gasca and F. de la Rosa T.

Affiliation: Computer Engineering College, University of Seville, Spain

Keyword(s): Diagnosis, Consistency, Conflict, Anomaly, Firewall, ACL, Ruleset, Update.

Related Ontology Subjects/Areas/Topics: Enterprise Information Systems ; Formal Methods ; Information Systems Analysis and Specification ; Methodologies and Technologies ; Operational Research ; Security ; Simulation and Modeling ; Software Agents and Internet Computing ; Telecommunications ; Wireless and Mobile Computing ; Wireless and Mobile Technologies ; Wireless Information Networks and Systems

Abstract: Filtering is a very important issue in next generation networks. These networks consist of a relatively high number of resource constrained devices and have special features, such as management of frequent topology changes. At each topology change, the access control policy of all nodes of the network must be automatically modified. In order to manage these access control requirements, Firewalls have been proposed by several researchers. However, many of the problems of traditional firewalls are aggravated due to these networks particularities, as is the case of ACL consistency. A firewall ACL with inconsistencies implies in general design errors, and indicates that the firewall is accepting traffic that should be denied or vice versa. This can result in severe problems such as unwanted accesses to services, denial of service, overflows, etc. Detecting inconsistencies is of extreme importance in the context of highly sensitive applications (e.g. health care). We propose a local incon sistency detection algorithm and data structures to prevent automatic rule updates that can cause inconsistencies. The proposal has very low computational complexity as both theoretical and experimental results will show, and thus can be used in real time environments. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 18.219.112.111

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Pozo, S.; M. Gasca, R. and de la Rosa T., F. (2009). EFFICIENT DATA STRUCTURES FOR LOCAL INCONSISTENCY DETECTION IN FIREWALL ACL UPDATES. In Proceedings of the 11th International Conference on Enterprise Information Systems - Volume 1: ICEIS; ISBN 978-989-8111-86-9; ISSN 2184-4992, SciTePress, pages 176-181. DOI: 10.5220/0001996001760181

@conference{iceis09,
author={S. Pozo. and R. {M. Gasca}. and F. {de la Rosa T.}.},
title={EFFICIENT DATA STRUCTURES FOR LOCAL INCONSISTENCY DETECTION IN FIREWALL ACL UPDATES},
booktitle={Proceedings of the 11th International Conference on Enterprise Information Systems - Volume 1: ICEIS},
year={2009},
pages={176-181},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0001996001760181},
isbn={978-989-8111-86-9},
issn={2184-4992},
}

TY - CONF

JO - Proceedings of the 11th International Conference on Enterprise Information Systems - Volume 1: ICEIS
TI - EFFICIENT DATA STRUCTURES FOR LOCAL INCONSISTENCY DETECTION IN FIREWALL ACL UPDATES
SN - 978-989-8111-86-9
IS - 2184-4992
AU - Pozo, S.
AU - M. Gasca, R.
AU - de la Rosa T., F.
PY - 2009
SP - 176
EP - 181
DO - 10.5220/0001996001760181
PB - SciTePress