Ontology-Based Tools for Automating Integration and Validation of Firewall Rules

Autori: A.M. Ghiran, G.C. Silaghi, N. Tomai

Editorial: Witold Abramowicz, Springer Verlag, 12 BIS Conference, Lecture Notes in Business Information Processing, 21, p.37-48, 2009.


Firewalls are recognized as efficient instruments in deploying security in computer networks. But, they may become useless in cases when network administrators do not possess enough skills and expertise to properly configure them. Nowadays, firewall rules are integrated in the broader scope of enterprise security management. Thus, deriving correct and consistent rules for firewalls is mandatory and they need to be assimilated in the global security policy of the enterprise. In this paper we present tools for managing firewalls using ontologies and semantic-rich languages. With our approach, network managers can develop new firewall rules, automatically verify and validate their correctness and consistency and integrate them with previous existing rules.

Cuvinte cheie: Ontologies, firewall management, rule-based reasoning