Title
A Conflict Detection Method for IPv6 Time-Based Firewall Policy
Abstract
Firewalls have been a very important secure tool to protect networks against attacks, which usually filter the unauthorized traffic entering the secured network. The packet filtering based on a predefined collection of ordered rules. Along with the IPv6 protocol is widely used, and the security issues comes with it. Firewall for IPv6 network, as an important element to protect network security, it will be not able to filter packets correctly if there are conflicts that caused by the same packet matching two or more rules. In addition, a new kind of firewall with time constraint is used more and more widely by different firewall company, such as, ACLs of Cisco, Iptalbes of Linux, and the like. It is a hard work to manage the rules in IPv4 firewall policy, not to mention the rules in IPv6 time-based firewall policy. Many methods have been proposed to analyze and detect the conflicts of individual or distributed firewall policies. However, very few of them can deal with the time constraint of rules. Therefore, it is an urgent problem to detect the conflicts of the IPv6 time-based firewall policy. In order to solve this problem, we describe a method, which can analyze the IPv6 time-based firewall policy. We use a formal method to analyze the meaning of IPv6 time-based firewall policy. Next, we take the formal validation tool (SMT solver Z3) to detect all the possible conflicts between every two rules. Lastly, we developed an experimental system to evaluate the performance of our method.
Year
DOI
Venue
2019
10.1109/ISPA-BDCloud-SustainCom-SocialCom48970.2019.00069
2019 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA/BDCloud/SocialCom/SustainCom)
Keywords
DocType
ISBN
firewall policy,time-based,IPv6,SMT Solver
Conference
978-1-7281-4329-3
Citations 
PageRank 
References 
0
0.34
0
Authors
8
Name
Order
Citations
PageRank
Xue Zhang100.34
Yi Yin200.68
Wei Liu313243.16
Zhizhen Peng400.34
guoqiang zhang5134.06
Yun Wang610720.55
Yuichiro Tateiwa7136.80
Naohisa Takahashi812327.99