首页> 外文会议>IEEE Software Engineering Workshop >Offline Validation of Firewalls
【24h】

Offline Validation of Firewalls

机译:离线防火墙验证

获取原文
获取外文期刊封面目录资料

摘要

This paper introduces a simulation environment for testing firewall configurations without the need of an actual, complex network setup. It assists the user in defining the required rule set based on an existing, informal security concept and in validating the resulting setup virtually. Configurations consisting of network hosts and permitted or not permitted services are modeled using a graphical environment. A framework which supports model-driven development is used to visualize the resulting configuration in a single graph. Existing plug-ins can be used to check single nodes or the whole graph using model checking. Additionally it is possible to simulate the packet flow and track errors without actually setting up one of the network devices. Test cases may be defined manually, produced by an automatic packet generator or even imported from previously captured, genuine network traffic. Multiple operating systems and firewall products are supported without forcing the user to learn the implementation details between them.
机译:本文介绍了一种用于测试防火墙配置的仿真环境,而无需实际,复杂的网络设置。它帮助用户根据现有的非正式安全概念和虚拟验证生成的设置来定义所需的规则集。由网络主机和允许或不允许的服务组成的配置是使用图形环境建模的。支持模型驱动开发的框架用于在单个图形中可视化结果配置。现有插件可用于使用模型检查检查单节点或整个图形。此外,可以模拟分组流程和跟踪误差,而无需实际设置其中一个网络设备。可以手动定义测试用例,由自动分组生成器或甚至从先前捕获的真正网络流量导入。支持多个操作系统和防火墙产品,而无需强制用户学习它们之间的实现细节。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号