Usable Firewall Configuration.

Weiwei Geng, Scott Flinn, John DeDourek · NPARC · 2005

Configuration is perhaps the most important aspect of a firewall. It is often hard to fully understand the implications of a given configuration, giving rise to two problems: it is hard to write rules to enforce the expected security policy correctly, and it is hard to understand a set of rules to make necessary changes. In this paper, we briefly introduced the IP packet filtering firewall followed by an analysis of configuration problems. We review related work and discuss the effectiveness of other approaches from a practical perspective to further illustrate our solution. We then describe a solution that combines simulation, visualization and interaction and describe a prototype and an evaluation of the tool.

Read the paper · More papers on PaperTik