Management and translation of filtering security policies
نویسندگان
چکیده
Firewalls are essential elements for security policy enforcement in modern networks. However, managing a filtering security policy, especially for enterprise networks, has become complex and error-prone. Filtering rules have to be carefully written and organized in order to correctly implement the security policy and avoid policy anomalies. In this paper, we present a set of techniques and algorithms that provide (1) automatic anomaly discovery for rule conflicts and potential problems in legacy firewalls, (2) anomaly-free policy editing for rule insertion, modification and removal, and (3) concise translation of filtering rules to high-level textual description for user visualization and verification. These techniques significantly simplify the management of any generic firewall policy written as filtering rules, while minimizing network vulnerability due to filtering policy misconfiguration.
منابع مشابه
To Examine Dimensions of Social Networks’ Filtering Regulations in Iran’s law
Social networks play a significant role in today world. These sites affect different aspects of individual and social life of people and the national and even international levels. Accordingly, they are spreading, and will play more important role in the future life. This paper aims to examine the positive and negative effects of social networks’ filtering, that creates curiosity and has invers...
متن کاملTo Examine Dimensions of Social Networks’ Filtering Regulations in Iran’s law
Social networks play a significant role in today world. These sites affect different aspects of individual and social life of people and the national and even international levels. Accordingly, they are spreading, and will play more important role in the future life. This paper aims to examine the positive and negative effects of social networks’ filtering, that creates curiosity and has invers...
متن کاملSupporting Secure Canonical Upgrade Policies in Multilevel Secure Object Stores
Secure canonical upgrade policies are multilevel relabel policies that, under certain conditions, allow high-level subjects to update low-level security labels. This paper describes a scheme whereby these policies can be supported within the Message Filter Model for multilevel secure object-oriented database management systems.
متن کاملEnforcing RBAC Policies over Data Stored on Untrusted Server (Extended Version)
One of the security issues in data outsourcing is the enforcement of the data owner’s access control policies. This includes some challenges. The first challenge is preserving confidentiality of data and policies. One of the existing solutions is encrypting data before outsourcing which brings new challenges; namely, the number of keys required to access authorized resources, efficient policy u...
متن کاملThe relationship between demographic characteristics and motivational factors in employees\' social security hospitals of Mazandaran
Background: Health worker motivation has the potential to have a large impact on health system performance, and this depends on some factors. The purpose of this study was to determine the factors affecting this motivation. Methods: From Winter 2013 to Spring 2014, 1046 employees and physicians (439 males and 607 females) with a mean age of 36 and 37.2 years in men and women, respective...
متن کامل