Firmato:: A novel firewall management toolkit

被引:90
作者
Bartal, Y [1 ]
Mayer, A [1 ]
Nissim, K [1 ]
Wool, A [1 ]
机构
[1] AT&T Bell Labs, Lucent Technol, Murray Hill, NJ 07974 USA
来源
PROCEEDINGS OF THE 1999 IEEE SYMPOSIUM ON SECURITY AND PRIVACY | 1999年
关键词
D O I
10.1109/SECPRI.1999.766714
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years packet-filtering firewalls have seen some impressive technological advances (e.g., stateful inspection, transparency, performance etc.) and wide-spread deployment. In contrast, firewall and security management technology is lacking. In this paper we present Firmato, a firewall management toolkit, with the following distinguishing properties and components: (1) an entity-relationship model containing, in a unified form, global knowledge of the security policy and of the network topology; (2) a model definition language, which we use as an interface to define an instance of the entity-relationship model; (3) a model compiler; translating the global knowledge of the model into firewall-specific configuration files; and (4) a graphical firewall rule illustrator We demonstrate Firmato's capabilities on a realistic example, thus showing that firewall management can be done successfully at an appropriate level of abstraction. We implemented our toolkit to work with a commercially available firewall product. We believe that our approach is an important step towards streamlining the process of configuring and managing firewalls, especially in complex, multi-firewall installations.
引用
收藏
页码:17 / 31
页数:15
相关论文
共 19 条
  • [1] Firewalls: An expert roundtable
    Anderson, JP
    Brand, S
    Gong, L
    Haigh, T
    Lipner, S
    Lunt, T
    Nelson, R
    Neugent, W
    Orman, H
    Ranum, M
    Schell, R
    Spafford, E
    [J]. IEEE SOFTWARE, 1997, 14 (05) : 60 - 66
  • [2] Carney M, 1998, PROCEEDINGS OF THE SEVENTH USENIX SECURITY SYMPOSIUM, P1
  • [3] Chapman D., 1995, Building internet firewalls
  • [4] Cheswick WilliamR., 1994, FIREWALLS INTERNET S
  • [5] FREMONT A, 1998, NET PARTITIONER 3 1
  • [6] FROHLICH M, 1998, GRAPH VISUALIZATION
  • [7] FULMER C, 1998, FIREWALL PRODUCT OVE
  • [8] GUTTMAN JD, 1997, P IEEE S SEC PRIV OA
  • [9] HOWE CD, 1996, FORRESTER REPORT, V10
  • [10] LAKSHMAN TV, 1998, P ACM SIGCOMM VANC B