Firmato: A novel firewall management toolkit

Yair Bartal, Alain Mayer, Kobbi Nissim, Avishai Wool

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

98 Scopus citations

Abstract

In recent years, packet filtering firewalls have seen some impressive technological advances (e.g., stateful inspection, transparency, performance, etc.) and widespread deployment. In contrast, firewall and security management technology is lacking. We present Firmato, a firewall management toolkit, with the following distinguishing properties and components: (1) an entity relationship model containing, in a unified form, global knowledge of the security policy and of the network topology; (2) a model definition language, which we use as an interface to define an instance of the entity relationship model; (3) a model compiler translating the global knowledge of the model into firewall-specific configuration files; and (4) a graphical firewall rule illustrator. We demonstrate Firmato's capabilities on a realistic example, thus showing that firewall management can be done successfully at an appropriate level of abstraction. We implemented our toolkit to work with a commercially available firewall product. We believe that our approach is an important step towards streamlining the process of configuring and managing firewalls, especially in complex, multi firewall installations.

Original languageEnglish
Title of host publicationProceedings of the 1999 IEEE Symposium on Security and Privacy
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages17-31
Number of pages15
ISBN (Electronic)0769501761
DOIs
StatePublished - 1999
Externally publishedYes
Event1999 IEEE Symposium on Security and Privacy - Oakland, United States
Duration: 9 May 199912 May 1999

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
Volume1999-January
ISSN (Print)1081-6011

Conference

Conference1999 IEEE Symposium on Security and Privacy
Country/TerritoryUnited States
CityOakland
Period9/05/9912/05/99

Bibliographical note

Publisher Copyright:
© 1999 IEEE.

Fingerprint

Dive into the research topics of 'Firmato: A novel firewall management toolkit'. Together they form a unique fingerprint.

Cite this