Title
FIREMAN: A Toolkit for FIREwall Modeling and ANalysis
Abstract
Security concerns are becoming increasingly critical in networked systems. Firewalls provide important defense for network security. However, misconfigurations in firewalls are very common and significantly weaken the desired security. This paper introduces FIREMAN, a static analysis toolkit for firewall modeling and analysis. By treating firewall configurations as specialized programs, FIREMAN applies static analysis techniques to check misconfigurations, such as policy violations, inconsistencies, and inefficiencies, in individual firewalls as well as among distributed firewalls. FIREMAN performs symbolic model checking of the firewall configurations for all possible IP packets and along all possible data paths. It is both sound and complete because of the finite state nature of firewall configurations. FIREMAN is implemented by modeling firewall rules using binary decision diagrams (BDDs), which have been used successfully in hardware verification and model checking. We have experimented with FIREMAN and used it to uncover several real misconfigurations in enterprise networks, some of which have been subsequently confirmed and corrected by the administrators of these networks.
Year
DOI
Venue
2006
10.1109/SP.2006.16
IEEE Symposium on Security and Privacy
Keywords
Field
DocType
firewall modeling,static analysis toolkit,security concern,real misconfigurations,model checking,firewall configuration,static analysis technique,network security,individual firewalls,firewall rule,routing,binary decision diagram,data structures,static analysis,data security,hardware,filtering,data privacy,production,boolean functions
Data security,Model checking,Firewall (construction),Computer science,Computer security,Network packet,Network security,Static analysis,Application firewall,Stateful firewall
Conference
ISSN
ISBN
Citations 
1081-6011
0-7695-2574-1
191
PageRank 
References 
Authors
10.23
19
6
Search Limit
100191
Name
Order
Citations
PageRank
Lihua Yuan181036.52
Jianning Mai234218.63
Zhendong Su33397175.76
Hao Chen42723183.89
Chen-Nee Chuah52006161.34
Prasant Mohapatra64344304.46