Automated Firewall Rule Set Generation Through Passive Traffic Inspection.
George-Christian Pranschke, Barry V. W. Irwin, Richard J. Barnett · 2009
Introducing rewalls and other choke point controls in existing networks is often problematic, because in the majority of cases there is already production tra c in place that cannot be interrupted. This often necessitates the time consuming manual analysis of network tra c in order to ensure that when a new system is installed, there is no disruption to legitimate ows. To improve upon this situation it is proposed that a system facilitating network tra c analysis and rewall rule set generation is developed. A high level overview of the implementation of the components of such a system is presented. The system makes use of a third party package, named Firewall Builder which provides rewall rule sets for a wide variety of rewalling solutions. Additions to the system are scoring metrics which may assist the administrator to optimise the rule sets for the most e cient matching of ows, based on tra c volume, frequency or packet count. KEY WORDS c anal-rewall, choke point control, automatic con guration, network tra