Title
Firewall filtering rules analysis for anomalies detection
Abstract
Firewalls are key components in network security architectures. A firewall controls the access into and from the network based on a set of predefined filtering rules. Hence, choosing well defined and coherent filtering rules becomes the important factor towards the effectiveness of firewalls. In this paper, we propose an approach for detecting and correcting anomalies in firewalls filtering rules. In fact, we define a process that starts with defining a matrix to represent the list of the filtering rules, and then generates a number of matrices defining all the relationships among the filtering rules, where each matrix is related to a particular type of network packet's field. Finally, the process uses the matrices to detect and correct the anomalies within the filtering rules. Moreover, the paper addresses the issue of the ordering of the filtering rules.
Year
DOI
Venue
2008
10.1504/IJSN.2008.020090
IJSN
Keywords
Field
DocType
important factor,network security architecture,network packet,rules analysis,anomalies detection,particular type,key component,network security,anomaly detection,access control
Data mining,Anomaly detection,Firewall (construction),Computer security,Computer science,Network security,Network packet,Network architecture,Filter (signal processing),Access control,Security policy
Journal
Volume
Issue
Citations 
3
3
11
PageRank 
References 
Authors
0.63
4
4
Name
Order
Citations
PageRank
Adel Bouhoula157957.05
Zouheir Trabelsi213627.78
Ezedin Barka325721.71
Mohammed-Anis Benelbahri4110.63