Title
Assessing network authorization policies via reachability analysis.
Abstract
Evaluating if a computer network only permits allowed business operations without transmitting unwanted or malicious traffic is a crucial security task. Reachability analysis – the process that evaluates allowed communications – is a tool useful not only to discover security issues but also to identify network misconfigurations. This paper presents a novel approach to quantify network reachability based on the concept of equivalent firewall – a fictitious device, ideally connected directly to the communicating peers and whose policy summarizes the network behaviour between them – that can be queried to derive reachability information. We build equivalent firewalls by using a mathematical model that supports a large variety of network security controls (like NAT, NAPT, tunnels and filters up to the application layer) and allows an accurate analysis. The presented approach is efficient and highly scalable, as confirmed by tests with a large corporate network as well as synthetic networks.
Year
DOI
Venue
2017
10.1016/j.compeleceng.2017.02.019
Computers & Electrical Engineering
Keywords
Field
DocType
Network reachability,Authorization policies,Security policy assessment,Network modelling,Security assessment,Vulnerability analysis,Infrastructure security modelling,Risk analysis and management
Application layer,Network security policy,Computer science,Asset (computer security),Network security,Computer network,Network simulation,Security service,Reachability,Network Access Control
Journal
Volume
Issue
ISSN
64
C
0045-7906
Citations 
PageRank 
References 
5
0.44
18
Authors
5
Name
Order
Citations
PageRank
Cataldo Basile111414.90
Daniele Canavese2184.03
Christian Pitscheider3111.71
Antonio Lioy444453.41
Fulvio Valenza55411.17