Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

Abnormal Policy Detection and Correction Using Overlapping Transition

Authors
Kim, SunghyunLee, Heejo
Issue Date
5월-2010
Publisher
IEICE-INST ELECTRONICS INFORMATION COMMUNICATIONS ENG
Keywords
firewall; security policy; policy anomalies; network security; ACL
Citation
IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, v.E93D, no.5, pp.1053 - 1061
Journal Title
IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS
Volume
E93D
Number
5
Start Page
1053
End Page
1061
URI
https://scholar.korea.ac.kr/handle/2021.sw.korea/116555
DOI
10.1587/transinf.E93.D.1053
ISSN
1745-1361
Abstract
Policy in security devices such as firewalls and Network Intrusion Prevention Systems (NIPS) is usually implemented as a sequence of rules. This allows network packets to proceed or to be discarded based on rule's decision. Since attack methods are increasing rapidly, a huge number of security rules are generated and maintained in security devices. Under attack or during heavy traffic, the policy configured wrong creates security holes and prevents the system from deciding quickly whether to allow or deny a packet. Anomalies between the rules occur when there is overlap among the rules. In this paper, we propose a new method to detect anomalies among rules and generate new rules without configuration error in multiple security devices as well as in a single security device. The proposed method cuts the overlap regions among rules into minimum overlap regions and finds the abnormal domain regions of rules' predicates. Classifying rules by the network traffic flow, the proposed method not only reduces computation overhead but blocks unnecessary traffic among distributed devices.
Files in This Item
There are no files associated with this item.
Appears in
Collections
Graduate School > Department of Computer Science and Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Lee, Hee jo photo

Lee, Hee jo
컴퓨터학과
Read more

Altmetrics

Total Views & Downloads

BROWSE