MIRAGE: A management tool for the analysis and deployment of network security policies

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

We present the core functionality of MIRAGE, a management tool for the analysis and deployment of configuration policies over network security components, such as firewalls, intrusion detection systems, and VPN routers. We review the two main functionalities embedded in our current prototype: (1) a bottom-up analysis of already deployed network security configurations and (2) a top-down refinement of global policies into network security component configurations. In both cases, MIRAGE provides intra-component analysis to detect inconsistencies in single component deployments; and inter-component analysis, to detect multi-component deployments which are not consistent. MIRAGE also manages the description of the security architecture topology, to guarantee the proper execution of all the processes.

Original languageEnglish
Title of host publicationData Privacy Management and Autonomous Spontaneous Security - 5th International Workshop, DPM 2010 and 3rd International Workshop, SETOP 2010, Revised Selected Papers
PublisherSpringer Verlag
Pages203-215
Number of pages13
ISBN (Print)9783642193477
DOIs
Publication statusPublished - 1 Jan 2011
Externally publishedYes
Event5th International Workshop on Data Privacy Management, DPM 2010 and 3rd International Workshop on Autonomous and Spontaneous Security, SETOP 2010 - Athens, Greece
Duration: 23 Sept 2010 → …

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6514 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference5th International Workshop on Data Privacy Management, DPM 2010 and 3rd International Workshop on Autonomous and Spontaneous Security, SETOP 2010
Country/TerritoryGreece
CityAthens
Period23/09/10 → …

Keywords

  • Access control
  • Analysis of configurations
  • Network security
  • OrBAC
  • Policy refinement

Fingerprint

Dive into the research topics of 'MIRAGE: A management tool for the analysis and deployment of network security policies'. Together they form a unique fingerprint.

Cite this