Skip to main navigation Skip to search Skip to main content

FireCracker: A framework for inferring firewall policies using smart probing

  • Taghrid Samak*
  • , Adel El-Atawy
  • , Ehab Al-Shaer
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

21 Scopus citations

Abstract

A firewall policy that is correct and complete is crucial to the safety of a computer network. An adversary will benefit a lot from knowing the policy or its semantics. In this paper, we propose a framework that could be used to blindly discover a firewall policy remotely as a black box and without prior knowledge about the network configuration. We show how an attacker can reconstruct a firewall's policy by probing the firewall with tailored packets into a network and forming an idea of what the policy looks like. The proposed methodology shows how to discover a policy that is semantically equivalent to the original one used in the deployed firewall. Three techniques are proposed for reconstructing the policy as well as to intelligently choose the probing packets adaptively based on the firewall response. We show the possibility of obtaining the deployed policy in a feasible time with acceptable accuracy.

Original languageEnglish
Title of host publicationProceedings - 15th IEEE International Conference on Network Protocols, ICNP 2007
Pages294-303
Number of pages10
DOIs
StatePublished - 2007
Externally publishedYes

Publication series

NameProceedings - International Conference on Network Protocols, ICNP
ISSN (Print)1092-1648

ASJC Scopus subject areas

  • General Engineering

Fingerprint

Dive into the research topics of 'FireCracker: A framework for inferring firewall policies using smart probing'. Together they form a unique fingerprint.

Cite this