Tree automata based semantics of firewalls - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2011

Tree automata based semantics of firewalls

Tony Bourdier

Résumé

Security constitutes a crucial concern in modern information systems. Several aspects are involved, such as user authentication (establishing and verifying users' identity), cryptology (changing secrets into unintelligible messages and back to the original secrets after transmission) and security policies (preventing illicit or forbidden accesses from users to information). Firewalls are a core element of network security policies, that is why their analysis has drawn many attention over the past decade. In this paper, we propose a new approach for analyzing firewalls, based on tree automata techniques: we show that the semantics of any process composing a firewall (including the network address translation functionality) can be expressed as a regular set or relation and thus can be denoted by a tree automaton. We also investigate abilities opened by tree automata based representations of the semantics of firewalls.
Fichier principal
Vignette du fichier
hal.pdf (562.23 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00460462 , version 1 (01-03-2010)
inria-00460462 , version 2 (25-05-2010)
inria-00460462 , version 3 (18-04-2011)

Identifiants

Citer

Tony Bourdier. Tree automata based semantics of firewalls. 6th International Conference on Network Architectures and Information Systems Security, 2011, La Rochelle, France. pp.171--178, ⟨10.1109/SAR-SSI.2011.5931363⟩. ⟨inria-00460462v3⟩
150 Consultations
229 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More