Skip to main navigation Skip to search Skip to main content

Build and test your own network configuration

  • Saeed Al-Haj*
  • , Padmalochan Bera
  • , Ehab Al-Shaer
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Access control policies play a critical role in the security of enterprise networks deployed with variety of policy-based devices (e.g., routers, firewalls, and IPSec). Usually, the security policies are configured in the network devices in a distributed fashion through sets of access control lists (ACL). However, the increasing complexity of access control configurations due to larger networks and longer policies makes configuration errors inevitable. Incorrect policy configuration makes the network vulnerable to different attacks and security breaches. In this paper, we present an imperative framework, namely, ConfigLEGO, that provides an open programming platform for building the network security configuration globally and analyzing it systematically. The ConfigLEGO engine uses Binary Decision Diagram (BDD) to build a Boolean model that represents the global system behaviors including all possible interaction between various components in extensible and scalable manner. Our tool also provides a C/C++ API as a software wrapper on top of the BDD engine to allow users in defining topology, configurations, and reachability, and then analyzing in various abstraction levels, without requiring knowledge of BDD representation or operations.

Original languageEnglish
Title of host publicationSecurity and Privacy in Communication Networks - 7th International ICST Conference, SecureComm 2011, Revised Selected Papers
Pages522-532
Number of pages11
DOIs
StatePublished - 2012
Externally publishedYes
Event7th International ICST Conference on Security and Privacy in Communication Networks, SecureComm 2011 - London, United Kingdom
Duration: 7 Sep 20119 Sep 2011

Publication series

NameLecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering
Volume96 LNICST
ISSN (Print)1867-8211

Conference

Conference7th International ICST Conference on Security and Privacy in Communication Networks, SecureComm 2011
Country/TerritoryUnited Kingdom
CityLondon
Period7/09/119/09/11

Keywords

  • BDDs
  • Formal methods
  • Imperative analysis
  • Network configuration

ASJC Scopus subject areas

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Build and test your own network configuration'. Together they form a unique fingerprint.

Cite this