Authors
JeeHyun Hwang, Tao Xie, Fei Chen, Alex X Liu
Publication date
2012/1/24
Journal
IEEE Transactions on Network and Service Management
Volume
9
Issue
1
Pages
1-11
Publisher
IEEE
Description
Firewalls are the mainstay of enterprise security and the most widely adopted technology for protecting private networks. As the quality of protection provided by a firewall directly depends on the quality of its policy (i.e., configuration), ensuring the correctness of firewall policies is important and yet difficult. To help ensure the correctness, we propose a systematic structural testing approach for firewall policies. We define structural coverage (based on coverage criteria of rules, predicates, and clauses) on the firewall policy under test. To achieve high structural coverage effectively, we have developed four automated packet generation techniques: the random packet generation, the one based on local constraint solving (considering individual rules locally in a policy), the one based on global constraint solving (considering multiple rules globally in a policy), and the one based on boundary values. We have conducted …
Total citations
20122013201420152016201720182019202020212022113432411
Scholar articles
JH Hwang, T Xie, F Chen, AX Liu - IEEE Transactions on Network and Service …, 2012