White Papers

Firewall Policy Reconstruction by Active Probing: An Attacker's View

Category: Security

Tags: firewall, network

Overview Having a firewall policy that is correct and complete is crucial to the safety of the computer network. An adversary will benefit a lot from knowing the policy or its semantics. This paper shows how an attacker can reconstruct a firewall's policy by probing the firewall by sending tailored packets into a network and forming an idea of what the policy looks like. It presents two approaches of compiling this information into a policy that can be arbitrary close to the original one used in the deployed firewall. The first approach is based on region growing from single firewall response to sample packets. The other approach uses split-and-merge in order to divide the space of the firewall's rules and analyzes each independently.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
DePaul University
File Format
PDF
Date Published
Apr 23, 2008
Format
White Papers
Topics
Firewalls, Network Security, Security Tools

Similiar White Papers

Balancing Security Against Productivity

Balancing Security Against Productivity

What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending atta

Publisher: Novell  |  Tags: management, security management

Security: New strides in preventing intrusions.

Security: New strides in preventing intrusions.

Need help eliminating risk in your IT environment? This ForwardView webshow describes how security appliances, which inc

Publisher: IBM

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Still super gluing your USB ports shut? Unauthorized access to networks, lost or stolen laptops and other mobile hardwar

Publisher: Novell  |  Tags: usb

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Unauthorized access to networks, lost or stolen laptops and other mobile hardware, and theft of proprietary informati

Publisher: Novell  |  Tags: laptop, mobile devices

Firewall Rules Analysis

Firewall Rules Analysis

This paper proposes a method to analyze the firewall policy or rule-set using Relational Algebra and Raining 2D-Box Mode

Publisher: Mahasarakham University  |  Tags: check point, firewall

DePaul University White Papers

Modeling and Verification of IPSec and VPN Security Policies

Modeling and Verification of IPSec and VPN Security Policies

IPSec has become the defacto standard protocol for secure Internet communications, providing traffic integrity, confiden

Publisher: DePaul University  |  Tags: authentication, network, vpn

A New Approach to Developing High-Availability Server

A New Approach to Developing High-Availability Server

This paper presents a new approach to developing High Availability (HA) server using Rapid Spanning Tree Algorithm and P

Publisher: DePaul University  |  Tags: applications, ip, management, server, software

A Study of Mobile Internet Usage From Utilitarian and Hedonic User Tendency Perspectives

A Study of Mobile Internet Usage From Utilitarian and Hedonic User Tendency Perspectives

Although a few studies have focused on mobile value from the distinctive feature of a wireless mobile technology perspec

Publisher: DePaul University  |  Tags: mobile technology

Firewall Policy Advisor for Anomaly Discovery and Rule Editing

Firewall Policy Advisor for Anomaly Discovery and Rule Editing

Firewalls are core elements in network security. However, managing firewall rules, especially for enterprize networks, h

Publisher: DePaul University  |  Tags: firewall, network, network security, security policy, updates

A Novel Quantitative Approach for Measuring Network Security

A Novel Quantitative Approach for Measuring Network Security

Evaluation of network security is an essential step in securing any network. This evaluation can help security professio

Publisher: DePaul University  |  Tags: network, network security