Firmato:: A novel firewall management toolkit

被引:90
作者
Bartal, Y [1 ]
Mayer, A [1 ]
Nissim, K [1 ]
Wool, A [1 ]
机构
[1] AT&T Bell Labs, Lucent Technol, Murray Hill, NJ 07974 USA
来源
PROCEEDINGS OF THE 1999 IEEE SYMPOSIUM ON SECURITY AND PRIVACY | 1999年
关键词
D O I
10.1109/SECPRI.1999.766714
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years packet-filtering firewalls have seen some impressive technological advances (e.g., stateful inspection, transparency, performance etc.) and wide-spread deployment. In contrast, firewall and security management technology is lacking. In this paper we present Firmato, a firewall management toolkit, with the following distinguishing properties and components: (1) an entity-relationship model containing, in a unified form, global knowledge of the security policy and of the network topology; (2) a model definition language, which we use as an interface to define an instance of the entity-relationship model; (3) a model compiler; translating the global knowledge of the model into firewall-specific configuration files; and (4) a graphical firewall rule illustrator We demonstrate Firmato's capabilities on a realistic example, thus showing that firewall management can be done successfully at an appropriate level of abstraction. We implemented our toolkit to work with a commercially available firewall product. We believe that our approach is an important step towards streamlining the process of configuring and managing firewalls, especially in complex, multi-firewall installations.
引用
收藏
页码:17 / 31
页数:15
相关论文
共 19 条
[1]   Firewalls: An expert roundtable [J].
Anderson, JP ;
Brand, S ;
Gong, L ;
Haigh, T ;
Lipner, S ;
Lunt, T ;
Nelson, R ;
Neugent, W ;
Orman, H ;
Ranum, M ;
Schell, R ;
Spafford, E .
IEEE SOFTWARE, 1997, 14 (05) :60-66
[2]  
Carney M, 1998, PROCEEDINGS OF THE SEVENTH USENIX SECURITY SYMPOSIUM, P1
[3]  
Chapman D., 1995, Building internet firewalls
[4]  
Cheswick WilliamR., 1994, FIREWALLS INTERNET S
[5]  
FREMONT A, 1998, NET PARTITIONER 3 1
[6]  
FROHLICH M, 1998, GRAPH VISUALIZATION
[7]  
FULMER C, 1998, FIREWALL PRODUCT OVE
[8]  
GUTTMAN JD, 1997, P IEEE S SEC PRIV OA
[9]  
HOWE CD, 1996, FORRESTER REPORT, V10
[10]  
LAKSHMAN TV, 1998, P ACM SIGCOMM VANC B