TY - GEN
T1 - FireCracker
T2 - A framework for inferring firewall policies using smart probing
AU - Samak, Taghrid
AU - El-Atawy, Adel
AU - Al-Shaer, Ehab
PY - 2007
Y1 - 2007
N2 - A firewall policy that is correct and complete is crucial to the safety of a computer network. An adversary will benefit a lot from knowing the policy or its semantics. In this paper, we propose a framework that could be used to blindly discover a firewall policy remotely as a black box and without prior knowledge about the network configuration. We show how an attacker can reconstruct a firewall's policy by probing the firewall with tailored packets into a network and forming an idea of what the policy looks like. The proposed methodology shows how to discover a policy that is semantically equivalent to the original one used in the deployed firewall. Three techniques are proposed for reconstructing the policy as well as to intelligently choose the probing packets adaptively based on the firewall response. We show the possibility of obtaining the deployed policy in a feasible time with acceptable accuracy.
AB - A firewall policy that is correct and complete is crucial to the safety of a computer network. An adversary will benefit a lot from knowing the policy or its semantics. In this paper, we propose a framework that could be used to blindly discover a firewall policy remotely as a black box and without prior knowledge about the network configuration. We show how an attacker can reconstruct a firewall's policy by probing the firewall with tailored packets into a network and forming an idea of what the policy looks like. The proposed methodology shows how to discover a policy that is semantically equivalent to the original one used in the deployed firewall. Three techniques are proposed for reconstructing the policy as well as to intelligently choose the probing packets adaptively based on the firewall response. We show the possibility of obtaining the deployed policy in a feasible time with acceptable accuracy.
UR - https://www.scopus.com/pages/publications/48349116472
U2 - 10.1109/ICNP.2007.4375860
DO - 10.1109/ICNP.2007.4375860
M3 - Conference contribution
AN - SCOPUS:48349116472
SN - 1424415888
SN - 9781424415885
T3 - Proceedings - International Conference on Network Protocols, ICNP
SP - 294
EP - 303
BT - Proceedings - 15th IEEE International Conference on Network Protocols, ICNP 2007
ER -