International Journal of Communications, Network and System Sciences

Volume 4, Issue 11 (November 2011)

ISSN Print: 1913-3715   ISSN Online: 1913-3723

Google-based Impact Factor: 1.39  Citations  

A Topology-Based Conflict Detection System for Firewall Policies using Bit-Vector-Based Spatial Calculus

HTML  Download Download as PDF (Size: 352KB)  PP. 683-695  
DOI: 10.4236/ijcns.2011.411084    4,917 Downloads   8,750 Views  Citations

Affiliation(s)

.

ABSTRACT

Firewalls use packet filtering to either accept or deny packets on the basis of a set of predefined rules called filters. The firewall forms the initial layer of defense and protects the network from unauthorized access. However, maintaining firewall policies is always an error prone task, because the policies are highly complex. Conflict is a misconfiguration that occurs when a packet matches two or more filters. The occurrence of conflicts in a firewall policy makes the filters either redundant or shadowed, and as a result, the network does not reflect the actual configuration of the firewall policy. Hence, it is necessary to detect conflicts to keep the filters meaningful. Even though geometry-based conflict detection provides an exhaustive method for error classification, when the number of filters and headers increases, the demands on memory and computation time increase. To solve these two issues, we make two main contributions. First, we propose a topology-based conflict detection system that computes the topological relationship of the filters to detect the conflicts. Second, we propose a systematic implementation method called BISCAL (a bit-vector-based spatial calculus) to implement the proposed system and remove irrelevant data from the conflict detection computation. We perform a mathematical analysis as well as experimental evaluations and find that the amount of data needed for topology is only one-fourth of that needed for geometry.

Share and Cite:

S. Thanasegaran, Y. Yin, Y. Tateiwa, Y. Katayama and N. Takahashi, "A Topology-Based Conflict Detection System for Firewall Policies using Bit-Vector-Based Spatial Calculus," International Journal of Communications, Network and System Sciences, Vol. 4 No. 11, 2011, pp. 683-695. doi: 10.4236/ijcns.2011.411084.

Cited by

[1] SAIDE: Efficient application interference detection and elimination in SDN
2020
[2] A New Conflict Detection Tree Structure in the Firewall Rule Set
2018
[3] Đề xuất cấu trúc cây phát hiện xung đột trong tập luật của tường lửa
2018
[4] An analysis method of topological relations between Snort rules
Journal of Southeast University (English Edition), 2016
[5] 一种 Snort 规则间拓扑关系的分析方法
东南大学学报: 英文版, 2016
[6] 防火墙规则间包含关系的解析方法
2015
[7] Verification of firewall reconfiguration for virtual machines migrations in the cloud
Computer Networks, 2015
[8] Fast and Complete Conflict Detection for Packet Classifiers
2014
[9] A new approach to designing firewall based on multidimensional matrix
Concurrency and Computation: Practice and Experience, 2013

Copyright © 2025 by authors and Scientific Research Publishing Inc.

Creative Commons License

This work and the related PDF file are licensed under a Creative Commons Attribution 4.0 International License.