Objective metrics for firewall security: A holistic view

  • Mohammed Noraden Alsaleh
  • , Saeed Al-Haj
  • , Ehab Al-Shaer

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Firewalls are the primary security devices in cyber defense. Yet, the security of firewalls depends on the quality of protection provided by the firewall policy. The lack of metrics and attack incident data makes measuring the security of firewall policies a challenging task. In this paper, we present a new set of quantitative metrics that can be used to measure, as well as, compare the security level of firewall policies in an enterprise network. The proposed metrics measure the risk of attacks on the network that is imposed due to weaknesses in the firewall policy. We also measure the feasibility of mitigating or removing that risk. The presented metrics are proven to be (1) valid as compared with the ground truth, and (2) practically useful as each one implies actionable security hardening.

Original languageEnglish
Title of host publication2013 IEEE Conference on Communications and Network Security, CNS 2013
PublisherIEEE Computer Society
Pages470-477
Number of pages8
ISBN (Print)9781479908950
DOIs
StatePublished - 2013
Externally publishedYes

Publication series

Name2013 IEEE Conference on Communications and Network Security, CNS 2013

ASJC Scopus subject areas

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Objective metrics for firewall security: A holistic view'. Together they form a unique fingerprint.

Cite this