Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

Assessing network authorization policies via reachability analysis

Articolo
Data di Pubblicazione:
2017
Abstract:
Evaluating if a computer network only permits allowed business operations without transmitting unwanted or malicious traffic is a crucial security task. Reachability analysis - the process that evaluates allowed communications - is a tool useful not only to discover security issues but also to identify network misconfigurations. This paper presents a novel approach to quantify network reachability based on the concept of equivalent firewall - a fictitious device, ideally connected directly to the communicating peers and whose policy summarizes the network behaviour between them - that can be queried to derive reachability information. We build equivalent firewalls by using a mathematical model that supports a large variety of network security controls (like NAT, NAPT, tunnels and filters up to the application layer) and allows an accurate analysis. The presented approach is efficient and highly scalable, as confirmed by tests with a large corporate network as well as synthetic networks.
Tipologia CRIS:
01.01 Articolo in rivista
Keywords:
Authorization policies; Infrastructure security modelling; Network modelling; Network reachability; Risk analysis and management; Security assessment; Security policy assessment; Vulnerability analysis
Elenco autori:
Valenza, Fulvio
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/342383
Pubblicato in:
COMPUTERS & ELECTRICAL ENGINEERING
Journal
  • Dati Generali

Dati Generali

URL

http://www.scopus.com/record/display.url?eid=2-s2.0-85014026980&origin=inward
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.2.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)