An Open Source Solution for Testing NAT'd and Nested iptables Firewalls
نویسندگان
چکیده
As firewalls have increased in power and flexibility, the complexity of configuring them correctly has grown significantly. An error in the firewall configuration can compromise the security of the system or interfere with normal network activity. The chance of an error increases when coordinating multiple firewalls, because the interaction between filters may hide errors more easily noticed on a single firewall. Firewalls on many networks use network address translation, which further increases the complexity of the firewall policy and creates additional opportunities for errors. Because errors in the firewall configuration are often extremely costly in time and security, system administrators need tools for verifying and debugging their firewall policy. ITVal is a tool for analyzing iptables-based firewalls that provides a plain English query language for simple firewall analysis. In this work, we describe extensions to ITVal that allow it to process network address translation rules and analyze multiple firewalls connected sequentially. 113.137.10.3 113.137.10.4 113.137.10.2 19 2. 16 8. 1. 3 19 2. 16 8. 1. 2 19 2. 16 8. 1. 4 113.137.10.1 OUTSIDE WORLD
منابع مشابه
Semantics-Preserving Simplification of Real-World Firewall Rule Sets
The security provided by a firewall for a computer network almost completely depends on the rules it enforces. For over a decade, it has been a well-known and unsolved problem that the quality of many firewall rule sets is insufficient. Therefore, there are many tools to analyze them. However, we found that none of the available tools could handle typical, real-world iptables rulesets. This is ...
متن کاملAcceleration of IPTABLES Linux Packet Filtering using GPGPU
Firewalls are a piece of software or hardware that control access to organization networks. Packet filtering is placed in the heart of firewalls. It is performed by comparing each data packet against a rule set. In the high bandwidth networks, filtering becomes a time consuming task. In this situation, the packet filtering firewall can reduce the overall throughput and become a bottleneck. To s...
متن کاملA Framework for Enforcing User-Based Authorization Policies on Packet Filter Firewalls
Packet filter firewalls are fundamental elements to prevent unauthorized traffic to reach protected networks or hosts. However, they have to take decisions about packets based on their contents, and currently packets do not contain any information about the entity responsible for its generation. In this paper we propose a framework that tackle this problem. The framework adds extra information ...
متن کاملPerformance analysis of the Linux firewall in a host
Firewalls are one of the most commonly used security systems to protect networks and hosts. Most researchers have focused on analyzing the latency and throughput of router firewalls. Different from this approach, this research focuses on studying the performance impact and the sensitivity of the Linux firewall (iptables) for a single host. In order to be able to measure the performance and the ...
متن کاملDistrict Court of Munich I, Judgement of 19/05/2004 – file reference: 21 0 6123/04 (Open Source – effectiveness of GPL)
The plaintiff is a member of the Open Source Project “net-filter/iptables”. As the so-called “maintainer” he is/was primarily responsible for the development of the programme. It was the aim of the project, which was established in the middle of the year 1999 by the Australian Paul “Rusty” Russel, to replace the old LinuxFirewall (ipchains) with a modern, forward-looking and flexible architecture.
متن کامل