Policy segmentation for intelligent firewall testing

Adel El-Atawy*, Khaled Ibrahim, Hazem Hamed, Ehab Al-Shaer

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

41 Scopus citations

Abstract

Firewall development and implementation are constantly being improved to accommodate higher security and performance standards. Using reliable yet practical techniques for testing new packet filtering algorithms and firewall design implementations from a functionality point of view becomes necessary to assure the required security. In this paper, an efficient paradigm for automated testing of firewalls with respect to their internal implementation and security policies is proposed. We propose a novel firewall testing technique using policy-based segmentation of the traffic address space, which can intelligently adapt the test traffic generation to target potential erroneous regions in the firewall input space. We also show that our automated approach of test case generation, analyzing firewall logs and creating testing reports not only makes the problem solvable but also offers a significantly higher degree of confidence than random testing.

Original languageEnglish
Title of host publication2005 First Workshop on Secure Network Protocols, NPSec, held in conjunction with ICNP 2005
Subtitle of host publication13th IEEE International Conference on Network Protocols
Pages67-72
Number of pages6
DOIs
StatePublished - 2005
Externally publishedYes
Event2005 First Workshop on Secure Network Protocols, NPSec, held in conjunction with ICNP 2005: 13th IEEE International Conference on Network Protocols - Boston, MA, United States
Duration: 6 Nov 20056 Nov 2005

Publication series

Name2005 First Workshop on Secure Network Protocols, NPSec, held in conjunction with ICNP 2005: 13th IEEE International Conference on Network Protocols
Volume2005

Conference

Conference2005 First Workshop on Secure Network Protocols, NPSec, held in conjunction with ICNP 2005: 13th IEEE International Conference on Network Protocols
Country/TerritoryUnited States
CityBoston, MA
Period6/11/056/11/05

ASJC Scopus subject areas

  • General Engineering

Fingerprint

Dive into the research topics of 'Policy segmentation for intelligent firewall testing'. Together they form a unique fingerprint.

Cite this