A probing technique for discovering last-matching rules of a network firewall
Khaled Salah, Karim Asif Sattar, Mohammed H. Sqalli, Ehab S. Al-Shaer · 2008
In this paper we identify a potential probing technique for remotely discovering the last-matching rules of the security policy of a firewall. The last-matching rules are those rules that are located at the bottom of the ruleset of a firewall's security policy, and would require the most processing time by the firewall. If these rules are discovered, an attacker can potentially launch an effective low-rate DoS attack to trigger worst-case or near worst-case processing, and thereby overwhelming the firewall and bringing it to its knees. As a proof of concept, we developed a prototype program that implements the detection algorithm and validated its effectiveness experimentally.