Pregled bibliografske jedinice broj: 1204030
Systematic review of automatic translation of high- level security policy into firewall rules
Systematic review of automatic translation of high- level security policy into firewall rules // 2022 45th Jubilee International Convention on Information, Communication and Electronic Technology (MIPRO) Proceedings / Skala, Karolj (ur.).
Opatija: Institute of Electrical and Electronics Engineers (IEEE), 2022. str. 1211-1216 doi:10.23919/mipro55190.2022.9803570 (predavanje, međunarodna recenzija, cjeloviti rad (in extenso), znanstveni)
CROSBI ID: 1204030 Za ispravke kontaktirajte CROSBI podršku putem web obrasca
Naslov
Systematic review of automatic translation of high-
level security policy into firewall rules
Autori
Kovačević, Ivan ; Štengl, Bruno ; Groš, Stjepan
Vrsta, podvrsta i kategorija rada
Radovi u zbornicima skupova, cjeloviti rad (in extenso), znanstveni
Izvornik
2022 45th Jubilee International Convention on Information, Communication and Electronic Technology (MIPRO) Proceedings
/ Skala, Karolj - Opatija : Institute of Electrical and Electronics Engineers (IEEE), 2022, 1211-1216
Skup
45th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO 2022)
Mjesto i datum
Opatija, Hrvatska, 23.05.2022. - 27.05.2022
Vrsta sudjelovanja
Predavanje
Vrsta recenzije
Međunarodna recenzija
Ključne riječi
network security, security policy, firewall
Sažetak
Firewalls are security devices that perform network traffic filtering. They are ubiquitous in the industry and are a common method used to enforce organizational security policy. Security policy is specified on a high level of abstraction, with statements such as “web browsing is allowed only on workstations inside the office network”, and needs to be translated into low- level firewall rules to be enforceable. There has been a lot of work regarding optimization, analysis and platform independence of firewall rules, but an area that has seen much less success is automatic translation of high-level security policies into firewall rules. In addition to improving rules’ readability, such translation would make it easier to detect errors. This paper surveys of over twenty papers that aim to generate firewall rules according to a security policy specified on a higher level of abstraction. It also presents an overview of similar features in modern firewall systems. Most approaches define specialized domain languages that get compiled into firewall rule sets, with some of them relying on formal specification, ontology, or graphical models. The approaches' have improved over time, but there are still many drawbacks that need to be solved before wider application.
Izvorni jezik
Engleski
Znanstvena područja
Računarstvo
POVEZANOST RADA
Ustanove:
Fakultet elektrotehnike i računarstva, Zagreb