首页> 外文会议>12th IFIP/IEEE International Symposium on Integrated Network Management >A declarative approach for global network security configuration verification and evaluation
【24h】

A declarative approach for global network security configuration verification and evaluation

机译:一种用于全球网络安全配置验证和评估的声明性方法

获取原文

摘要

With the increasing number of security devices and rules in the network, the complexity of detecting and tracing network security configuration errors become a very challenging task. This in turn increases the potential of security breaches due to rule conflicts, requirement violations or lack of security hardening. Most of the existing tools are either limited in scope as they do not offer a global analysis of different network devices or hard to comprehensively use because these tools are not declarative. Declarative logic programming can readily express network configurations and security requirements for verification analysis. In this paper, we use Prolog to model the entire network security configurations including topology, routing, firewall and IPSec. This is implemented in a tool called ConfigAnalyzer, which was also evaluated with large network and policy sizes. The tool allows for verifying reachability and security properties in flexible and expressive manner. It also allows for evaluating security configurations in terms of accessibilities credentials and rules.
机译:随着网络中安全设备和规则数量的增加,检测和跟踪网络安全配置错误的复杂性成为一项非常具有挑战性的任务。反过来,这会增加由于规则冲突,违反要求或缺乏安全性强化而导致的违反安全性的可能性。大多数现有工具要么由于不能提供对不同网络设备的全局分析而受到范围限制,要么由于这些工具不是声明性工具而难以全面使用。声明式逻辑编程可以轻松表达网络配置和安全性要求,以进行验证分析。在本文中,我们使用Prolog对整个网络安全配置建模,包括拓扑,路由,防火墙和IPSec。这是在称为ConfigAnalyzer的工具中实现的,该工具也已通过大型网络和策略规模进行了评估。该工具允许以灵活且富有表现力的方式验证可达性和安全性。它还允许根据可访问性凭证和规则评估安全配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号