Verifying consistency between security policy and firewall policy by using a constraint satisfaction problem server

7Citations
Citations of this article
2Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Packet filtering in firewall either accepts or denies network packets based upon a set of pre-defined filters called firewall policy. Firewall policy is designed under the instruction of security policy. A network security policy is a generic document that outlines the needs for network access permissions. And it determines how firewall filters are designed. If inconsistencies exist between security policy and firewall policy, firewall policy could not filter packets exactly, and the network protected by the firewall will be affected. To resolve this problem, we propose a method mat represents security policy and firewall policy as Constraint Satisfaction Problem and constructs a consistency verification model, then uses a CSP solver to verify their consistency. We did some experiments to verify our proposed method, experimental results showed the effectiveness. © Springer-Verlag 2012.

Cite

CITATION STYLE

APA

Yin, Y., Xu, J., & Takahashi, N. (2012). Verifying consistency between security policy and firewall policy by using a constraint satisfaction problem server. In Lecture Notes in Electrical Engineering (Vol. 144 LNEE, pp. 135–145). https://doi.org/10.1007/978-3-642-27326-1_18

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free