On the Isofunctionality of Network Access Control Lists

Malek Belhaouane, Joaquín García-Alfaro, Hervé Debar · 2015

In a networking context, Access Control Lists (ACLs) refer to security rules associated to network equipment, such as routers, switches and firewalls. Methods and tools to automate the management of ACLs distributed among several equipment shall verify if the corresponding ACLs are functionally equivalent. In this paper, we address such a verification process. We present a formal method to verify when two ACLs are iso functional and illustrate our proposal over a practical example.

Read the paper · More papers on PaperTik