Sciweavers

SRDS
2008
IEEE

Systematic Structural Testing of Firewall Policies

13 years 11 months ago
Systematic Structural Testing of Firewall Policies
Firewalls are the mainstay of enterprise security and the most widely adopted technology for protecting private networks. As the quality of protection provided by a firewall directly depends on the quality of its policy (i.e., configuration), ensuring the correctness of firewall policies is important and yet difficult. To help ensure the correctness of a firewall policy, we propose a systematic structural testing approach for firewall policies. We define structural coverage (based on coverage criteria of rules, predicates, and clauses) on the policy under test. To achieve high structural coverage effectively, we have developed three automated packet generation techniques: the random packet generation, the one based on local constraint solving (considering individual rules locally in a policy), and the most sophisticated one based on global constraint solving (considering multiple rules globally in a policy). We have conducted an experiment on a set of real policies and a set of...
JeeHyun Hwang, Tao Xie, Fei Chen, Alex X. Liu
Added 01 Jun 2010
Updated 01 Jun 2010
Type Conference
Year 2008
Where SRDS
Authors JeeHyun Hwang, Tao Xie, Fei Chen, Alex X. Liu
Comments (0)