Authors
Yair Bartal, Alain Mayer, Kobbi Nissim, Avishai Wool
Publication date
2004/11/1
Journal
ACM Transactions on Computer Systems (TOCS)
Volume
22
Issue
4
Pages
381-420
Publisher
ACM
Description
In recent years packet-filtering firewalls have seen some impressive technological advances (e.g., stateful inspection, transparency, performance, etc.) and wide-spread deployment. In contrast, firewall and security management technology is lacking. In this paper we present Firmato, a firewall management toolkit, with the following distinguishing properties and components: (1) an entity-relationship model containing, in a unified form, global knowledge of the security policy and of the network topology; (2) a model definition language, which we use as an interface to define an instance of the entity-relationship model; (3) a model compiler, translating the global knowledge of the model into firewall-specific configuration files; and (4) a graphical firewall rule illustrator.
We implemented a prototype of our toolkit to work with several commercially available firewall products. This prototype was used to control an operational …
Total citations
1999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202466191521194137394445412930302126221815141371095
Scholar articles
Y Bartal, A Mayer, K Nissim, A Wool - ACM Transactions on Computer Systems (TOCS), 2004