Management of stateful firewall misconfiguration

Joaquin Garcia-Alfaro, Frédéric Cuppens, Nora Cuppens-Boulahia, Salvador Martinez, Jordi Cabot

Research output: Contribution to journalArticlepeer-review

Abstract

Firewall configurations are evolving into dynamic policies that depend on protocol states. As a result, stateful configurations tend to be much more error prone. Some errors occur on configurations that only contain stateful rules. Others may affect those holding both stateful and stateless rules. Such situations lead to configurations in which actions on certain packets are conducted by the firewall, while other related actions are not. We address automatic solutions to handle these problems. Permitted states and transitions of connection-oriented protocols (in essence, on any layer) are encoded as automata. Flawed rules are identified and potential modifications are provided in order to get consistent configurations. We validate the feasibility of our proposal based on a proof of concept prototype that automatically parses existing firewall configuration files and handles the discovery of flawed rules according to our approach.

Original languageEnglish
Pages (from-to)64-85
Number of pages22
JournalComputers and Security
Volume39
Issue numberPARTA
DOIs
Publication statusPublished - 21 Mar 2013
Externally publishedYes

Keywords

  • Access control
  • Anomalies
  • Firewalls
  • Iptables
  • Misconfiguration
  • Model-driven engineering
  • Netfilter
  • Network security
  • Stateful rules
  • Stateless rules

Fingerprint

Dive into the research topics of 'Management of stateful firewall misconfiguration'. Together they form a unique fingerprint.

Cite this