Title
Visual analysis of complex firewall configurations.
Abstract
Firewalls have become essential components in the security concept of almost any modern computer network. Due to their relevance and central location in the network, their programming logic often survives several generations of administrators and hardware. Understanding the logic behind a firewall configuration is thus an important but challenging task for a network administrator. In general, there is a tendency to add new rules while old rules are only rarely changed or removed due to unexpected consequences in the network. In this paper we present a visualization tool to support the network administrator in this complex task of understanding firewall rule sets and object group definitions. The tool consists of a hierarchical sunburst visualization, which logically groups rules or object groups according to their common characteristics, a color-linked configuration editor and classical tree view components for rules and object groups. All these components are interactively linked to enable both exploratory and hypotheses testing tasks aimed at understanding the complex functionality of a firewall configuration. To verify our design, we present two case studies on the analysis of rule usage and on nested object groups and collected feedback from five firewall administrators.
Year
DOI
Venue
2012
10.1145/2379690.2379691
VizSEC
Keywords
Field
DocType
network administrator,object group,firewall rule set,firewall administrator,complex firewall configuration,modern computer network,color-linked configuration editor,groups rule,firewall configuration,object group definition,visual analysis,nested object group
Data mining,Firewall (construction),Sunburst,Visualization,Computer science,Computer security,Application firewall,Network administrator,Logic programming,Statistical hypothesis testing,Tree view
Conference
ISSN
Citations 
PageRank 
2639-4359
8
0.58
References 
Authors
17
3
Name
Order
Citations
PageRank
Florian Mansmann158935.91
Timo Göbel280.58
William Cheswick3202.05