Model-based tool-assistance for packet-filter design

16Citations
Citations of this article
4Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The design of suitable packet-filters protecting subnets against network- based attacks is usually difficult and error-prone. Therefore, toolassistance shall facilitate the design task and shall contribute to the correctness of the filters, i.e., the filters should be consistent with the other security mechanisms of the computer network, in particular with its access control schemes. Moreover, they should just enable the corresponding necessary traffic. Our tool approach applies a three-layered model describing the access control and network topology aspects of the system on three levels of abstraction. Each lower layer refines its upper neighbour and is accompanied with access control models. At the top level, role based access control is applied. The lowest level specifies packet filter configurations which can be implemented by means of the Linux kernel extension IPchains. The derivation of filter configurations is substantially supported by tool assistance in the course of an interactive design process.

Cite

CITATION STYLE

APA

Lück, I., Schäfer, C., & Krumm, H. (2001). Model-based tool-assistance for packet-filter design. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 1995, pp. 120–136). Springer Verlag. https://doi.org/10.1007/3-540-44569-2_8

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free