Skip to Main content Skip to Navigation
New interface
Conference papers

Automatic Verification of Conformance of Firewall Configurations to Security Policies

Nihel Ben Youssef 1 Adel Bouhoula 1 Florent Jacquemard 2 
2 DAHU - Verification in databases
LSV - Laboratoire Spécification et Vérification [Cachan], Inria Saclay - Ile de France
Abstract : The configuration of firewalls is highly error prone and automated solution are needed in order to analyze its correctness. We propose a formal and automatic method for checking whether a firewall reacts correctly wrt a security policy given in an high level declarative language. When errors are detected, some feedback is returned to the user in order to correct the firewall configuration. Furthermore, the procedure verifies that no conflicts exist within the security policy. We show that our method is both correct and complete. Finally, it has been implemented in a prototype of verifier based on a satisfiability solver modulo theories (SMT). Experiment conducted on relevant case studies demonstrate the efficiency and scalability of the approach.
Document type :
Conference papers
Complete list of metadata

Cited literature [12 references]  Display  Hide  Download
Contributor : Florent Jacquemard Connect in order to contact the contributor
Submitted on : Tuesday, March 22, 2011 - 4:40:49 PM
Last modification on : Thursday, January 20, 2022 - 4:13:06 PM
Long-term archiving on: : Thursday, June 23, 2011 - 2:51:42 AM


Files produced by the author(s)



Nihel Ben Youssef, Adel Bouhoula, Florent Jacquemard. Automatic Verification of Conformance of Firewall Configurations to Security Policies. IEEE Symposium on Computers and Communications (ISCC), Jul 2009, Sousse, Tunisia. pp.526-531, ⟨10.1109/ISCC.2009.5202309⟩. ⟨inria-00578926⟩



Record views


Files downloads