1 research outputs found
Fast algorithms for consistency-based diagnosis of firewall rule sets
Firewalls provide the first line of defence of nearly
all networked institutions today. However, Firewall
ACL management suffer some problems that need to be
addressed in order to be effective. The most studied
one is rule set consistency. There is an inconsistency if
different actions can be taken on the same traffic,
depending on the ordering of the rules. In this paper a
new algorithm to diagnose inconsistencies in firewall
rule sets is presented. Although many algorithms have
been proposed to address this problem, the presented
one is a big improvement over them, due to its low
algorithmic and memory complexity, even in worst
case. In addition, there is no need to pre-process in
any way the rule set previous to the application of the
algorithms. We also present experimental results with
real rule sets that validate our proposal.Ministerio de Educaci贸n y Ciencia DPI2006-15476-C02-0