Authors: Dinesha Ranathunga 1 ; Matthew Roughan 1 ; Phil Kernick 2 ; Nick Falkner 1 ; Hung Nguyen 1 ; Marian Mihailescu 1 and Michelle McClintock 1

Affiliations: 1 University of Adelaide, Australia ; 2 CQR Consulting, Australia

Keyword(s): Security policy, Zone-Conduit model, SCADA security, Security management.

Related Ontology Subjects/Areas/Topics: Data and Application Security and Privacy ; Information and Systems Security ; Network Security ; Security Management ; Security Verification and Validation ; Wireless Network Security

Abstract: A common goal in network-management is security. Reliable security requires confidence in the level of protection provided. But, many obstacles hinder reliable security management; most prominent is the lack of built-in verifiability in existing management paradigms. This shortfall makes it difficult to provide assurance that the expected security outcome is consistent pre- and post-deployment. Our research tackles the problem from first principles: we identify the verifiability requirements of robust security management, evaluate the limitations of existing paradigms and propose a new paradigm with verifi- ability built in: Formally-Verifiable Policy-Defined Networking (FV-PDN). In particular, we pay attention to firewalls which protect network data and resources from unauthorised access. We show how FV-PDN can be used to configure firewalls reliably in mission critical networks to protect them from cyber attacks.


