Authors
Seny Kamara, Sonia Fahmy, Eugene Schultz, Florian Kerschbaum, Michael Frantzen
Publication date
2003/4/1
Journal
Computers & Security
Volume
22
Issue
3
Pages
214-232
Publisher
Elsevier Advanced Technology
Description
Firewalls protect a trusted network from an untrusted network by filtering traffic according to a specified security policy. A diverse set of firewalls is being used today. As it is infeasible to examine and test each firewall for all possible potential problems, a taxonomy is needed to understand firewall vulnerabilities in the context of firewall operations. This paper describes a novel methodology for analyzing vulnerabilities in Internet firewalls. A firewall vulnerability is defined as an error made during firewall design, implementation, or configuration, that can be exploited to attack the trusted network that the firewall is supposed to protect. We examine firewall internals, and cross-reference each firewall operation with causes and effects of weaknesses in that operation, analyzing twenty reported problems with available firewalls. The result of our analysis is a set of matrices that illustrate the distribution of firewall vulnerability …
Total citations
200320042005200620072008200920102011201220132014201520162017201820192020202120222023202415121012141715197121010101010636551
Scholar articles
S Kamara, S Fahmy, E Schultz, F Kerschbaum… - Computers & Security, 2003