On the Usability of Firewall Configuration
نویسنده
چکیده
The firewalls in an enterprise network must be configured correctly or the internal corporate network can be infiltrated, leading to serious security, financial and performance implications. However, firewall configuration is a complex and error-prone task. Configuration languages are like assembly languages: they are low-level and vendor-specific. Moreover, usually multiple firewalls must be configured to protect an enterprise network. This task has been compared to programming a distributed system with an assembly language. While many researchers have tackled the firewall configuration problem from various perspectives, including new models, languages and complete systems, little has been done from the usability standpoint. Recently, studies have demonstrated that administrators strongly prefer textual or command line interfaces (CLIs) over GUIs. Most administrators are reluctant to invest time to learn new models, languages or systems for their everyday tasks. In this paper, we study the firewall configuration problem from the usability perspective. We first propose models to measure the lexical and structural complexity of firewall configuration. Using these models, we examine where complexity lies in the configurations of real networks. With the assumption that CLI will remain as the main user interface for administrators, we suggest visualizations to make firewall configuration more usable.
منابع مشابه
Natural elements spatial configuration and content usage in urban park
Abstract Urban parks are important public multifunctional space used for a wide range of activities. The usage levels of parks depend on the spatial characteristics of the spaces, where its forms and occupancies are referred as the usage-spatial relationship. Natural elements spatial complexity and park usability is of interest in this study. A photo - questionnaire was conducted among 296 of p...
متن کاملArchitecting the Lumeta Firewall Analyzer
Practically every corporation that is connected to the Internet has at least one firewall, and often many more. However, the protection that these firewalls provide is only as good as the policy they are configured to implement. Therefore, testing, auditing, or reverseengineering existing firewall configurations should be important components of every corporation’s network security practice. Un...
متن کاملPoster: Expectations, Perceptions, and Misconceptions of Personal Firewalls
Personal firewalls are recognized as the first line of defense for personal computers. However, the protection they afford depends strongly on their correct configuration [4]. Therefore, their usability is key to their effectiveness. In particular, as users become increasingly mobile, it is important for them to be able to judge whether their computer is secure enough for the usage context at h...
متن کاملUsability Study of Windows Vista’s Firewall
Windows Vista is shipped with a built-in personal firewall. The firewall has lots of new features over its predecessor, XP’s firewall. But, previous studies showed that Vista’s firewall have a set of usability problems. The goal of this paper is to address the lack of a complete and validated prototype of improved Vista’s firewall interface. By providing a high-fidelity prototype that could be ...
متن کاملUsability and Security of Personal Firewalls
Effective security of a personal firewall depends on (1) the rule granularity and the implementation of the rule enforcement and (2) the correctness and granularity of user decisions at the time of an alert. A misconfigured or loosely configured firewall may be more dangerous than no firewall at all because of the user’s false sense of security. This study assesses effective security of 13 pers...
متن کامل