White Papers

Firewall Analysis With Policy-Based Host Classification

Category: Security

Tags: firewall, network

Overview For administrators of large systems, testing and debugging a firewall policy is a difficult process. The size and complexity of many firewall policies make manual inspection of the rule set tedious and error-prone. The complex interaction of conflicting rules can conceal serious errors that compromise the security of the network or interrupt the delivery of important services. Most existing tools for verifying the policy require the user to provide a detailed set of test cases or queries, which can sometimes be as difficult as verifying the policy by hand. Deriving a sufficiently comprehensive set of tests requires a detailed knowledge of potential vulnerabilities and a familiarity with the mechanics of the firewall.

Download White Paper

By downloading you agree to our Terms and Conditions. These include information regarding use of your personal data.

Publisher
College of William and Mary
File Format
PDF
Date Published
May 31, 2008
Format
White Papers
Topics
Firewalls, Network Security, Security Tools

Similiar White Papers

Balancing Security Against Productivity

Balancing Security Against Productivity

What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending atta

Publisher: Novell  |  Tags: management, security management

Security: New strides in preventing intrusions.

Security: New strides in preventing intrusions.

Need help eliminating risk in your IT environment? This ForwardView webshow describes how security appliances, which inc

Publisher: IBM

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Still super gluing your USB ports shut? Unauthorized access to networks, lost or stolen laptops and other mobile hardwar

Publisher: Novell  |  Tags: usb

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Unauthorized access to networks, lost or stolen laptops and other mobile hardware, and theft of proprietary informati

Publisher: Novell  |  Tags: laptop, mobile devices

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

X-Force®Threat Insight Quarterly Voice over Internet Protocol (VoIP) ? Find out what the threats and challenges are for anyone deploying VoIP

The X-Force Threat Insight Quarterly (Threat IQ) highlights the most significant threats and challenges facing security

Publisher: Internet Security Systems  |  Tags: homeland security, security flaws, voip

College of William and Mary White Papers

Adaptive Page Replacement to Protect Thrashing in Linux

Adaptive Page Replacement to Protect Thrashing in Linux

This paper proposes and implements a thrashing protection patch in Linux kernels, which makes replacement policy respons

Publisher: College of William and Mary  |  Tags: linux, os

Anti-Phishing in Offense and Defense

Anti-Phishing in Offense and Defense

Many anti-phishing mechanisms currently focus on helping users verify whether a web site is genuine. However, usability

Publisher: College of William and Mary  |  Tags: phishing, phishing sites

BodyQoS: Adaptive and Radio-Agnostic QoS for Body Sensor Networks

BodyQoS: Adaptive and Radio-Agnostic QoS for Body Sensor Networks

As wireless devices and sensors are increasingly deployed on people, researchers have begun to focus on wireless body-ar

Publisher: College of William and Mary  |  Tags: data, network, qos

HoneyIM: Fast Detection and Suppression of Instant Messaging Malware in Enterprise-Like Networks

HoneyIM: Fast Detection and Suppression of Instant Messaging Malware in Enterprise-Like Networks

Instant Messaging (IM) has been one of most frequently used malware attack vectors due to its popularity. Distinct from

Publisher: College of William and Mary  |  Tags: malware, network, server, social engineering

EquiLoad: A Load Balancing Policy for Clustered Web Servers

EquiLoad: A Load Balancing Policy for Clustered Web Servers

This paper presents a new strategy for the allocation of requests in clustered web servers, based on the size distributi

Publisher: College of William and Mary  |  Tags: data, time