Fast, Cheap, and in Control: Towards Pain-Free Security!
نویسندگان
چکیده
We hypothesize that it is possible to obtain significant gains in operational efficiency through the application of simple analysis techniques to firewall rule sets. This paper describes our experiences with a firewall analysis tool and metrics that we have designed and used to help manage large production rule sets. Firewall rule sets typically become increasingly unwieldy over time. It is common for firewalls to have hundreds, or even thousands, of rules. Not surprisingly, administrators have a hard time keeping track of how the rules interact with each other, resulting in many partially effective or completely ineffective rules, and unpredictable behavior. Our tool can be used to identify these problematic rules. Further, given two rule sets, our tool produces a comprehensive list of the traffic that is only permitted or denied by one rule set, rather than both. As such, we can compare the existing rule set with a second rule set containing the proposed changes. The administrator can then visually check if the difference in traffic patterns corresponds to what he or she intended in proposing the changes. Additionally our tool collects various metrics that help the administrator to gauge the ‘health’ of the firewall. The tool is designed to be extensible to multiple vendor products.
منابع مشابه
Fast, Cheap and In Control: A Step Towards Pain Free Security!
© Fast, Cheap and In Control: A Step Towards Pain Free Security! Sandeep Bhatt, Cat Okita, Prasad Rao HP Laboratories HPL-2008-111 firewall, network, security metrics We hypothesize that it is possible to obtain significant gains in operational efficiency through the application of simple analysis techniques to firewall rule sets. This paper describes our experiences with a firewall analysis to...
متن کاملCheap Control Problem of Linear Systems With Delays: A Singular Perturbation Approach
A quadratic cheap control of linear systems with multiple state delays is considered. This optimal control problem is transformed to an optimal control problem of singularly perturbed systems. A composite suboptimal control of the latter is designed based on its asymptotic decomposition into two much simpler parameter-free subproblems, the slow and fast ones. Using this composite control, a sub...
متن کاملDesigning an Expert System for Internet Connection Problems Troubleshooting for wired network users
Man, is living in an era that the knowledge is estimated to be doubled in a relatively short time. The fast rate of technology's growth in the "Century of information", is caused by fast growth of communication technologies like the internet which has become one of the best tools for a quick, cheap, effective and vastly supported communication. For an efficient and effective usage of tools and ...
متن کاملDesigning an Expert System for Internet Connection Problems Troubleshooting for wired network users
Man, is living in an era that the knowledge is estimated to be doubled in a relatively short time. The fast rate of technology's growth in the "Century of information", is caused by fast growth of communication technologies like the internet which has become one of the best tools for a quick, cheap, effective and vastly supported communication. For an efficient and effective usage of tools and ...
متن کاملبررسی اثر موسیقی در کاهش درد و طول مدت لیبر
Introduction: This randomized clinical trial (RCT) was conducted to evaluate whether use of music could reduce the pain and duration of labor. Methods: Between 2010 and 2011, a total of 99 women at 38 weeks or greater with spontaneous labor were randomized to fast music, slow music, and control groups. Labor pain was assessed on a visual analogue scale (VAS) at beginning of the active phase an...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2008