TY - GEN
T1 - Verified iptables firewall analysis
AU - Diekmann, Cornelius
AU - Michaelis, Julius
AU - Haslbeck, Maximilian
AU - Carle, Georg
N1 - Publisher Copyright:
© 2016 IFIP.
PY - 2016/6/21
Y1 - 2016/6/21
N2 - We present a fully verified firewall ruleset analysis framework. Ultimately, it computes minimal service matrices, i.e. graphs which partition the complete IPv4 address space and visualize the allowed accesses between partitions for a fixed service. Internally, we are working with a simplified firewall model and a core contribution is the translation of complex real-world iptables firewall rules into this model. The presented algorithms and translation are formally proven correct with the Isabelle theorem prover. A real-world evaluation demonstrates the applicability of our tool. Both the iptables-save datasets and the Isabelle formalization are publicly available.
AB - We present a fully verified firewall ruleset analysis framework. Ultimately, it computes minimal service matrices, i.e. graphs which partition the complete IPv4 address space and visualize the allowed accesses between partitions for a fixed service. Internally, we are working with a simplified firewall model and a core contribution is the translation of complex real-world iptables firewall rules into this model. The presented algorithms and translation are formally proven correct with the Isabelle theorem prover. A real-world evaluation demonstrates the applicability of our tool. Both the iptables-save datasets and the Isabelle formalization are publicly available.
UR - http://www.scopus.com/inward/record.url?scp=84982290613&partnerID=8YFLogxK
U2 - 10.1109/IFIPNetworking.2016.7497196
DO - 10.1109/IFIPNetworking.2016.7497196
M3 - Conference contribution
AN - SCOPUS:84982290613
T3 - 2016 IFIP Networking Conference (IFIP Networking) and Workshops, IFIP Networking 2016
SP - 252
EP - 260
BT - 2016 IFIP Networking Conference (IFIP Networking) and Workshops, IFIP Networking 2016
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2016 IFIP Networking Conference (IFIP Networking) and Workshops, IFIP Networking 2016
Y2 - 17 May 2016 through 19 May 2016
ER -