Classifying Rules by In-out Traffic Direction to Avoid Security Policy Anomaly

Классификация правил по направлению входящего/исходящего трафика для предотвращения аномалий политик безопасности
Sunghyun Kim
2010-01-01

Intrusion Prevention Systemsfirewallsin-out traffic classificationpolicy anomaliessecurity devices
The continuous growth of attacks in the Internet causes to generate a number of rules in security devices such as Intrusion Prevention Systems, firewalls, etc. Policy anomalies in security devices create security holes and prevent the system from determining quickly whether allow or deny a packet. Policy anomalies exist among the rules in multiple security devices as well as in a single security device. The solution for policy anomalies requires complex and complicated algorithms. In this paper, we propose a new method to remove policy anomalies in a single security device and avoid policy anomalies among the rules in distributed security devices. The proposed method classifies rules according to traffic direction and checks policy anomalies in each device. It is unnecessary to compare the rules for outgoing traffic with the rules for incoming traffic. Therefore, classifying rules by in-out traffic, the proposed method can reduce the number of rules to be compared up to a half. Instead of detecting policy anomalies in distributed security devices, one adopts the rules from others for avoiding anomaly. After removing policy anomalies in each device, other firewalls can keep the policy consistency without anomalies by adopting the rules of a trusted firewall. In addition, it blocks unnecessary traffic because a source side sends as much traffic as the destination side accepts. Also we explain another policy anomaly which can be found under a connection-oriented communication protocol.
1
Adopting rules from a trusted firewall additionally blocks unnecessary traffic because sources send only what destinations accept.
2
Classifying security rules by incoming vs outgoing traffic direction allows checking anomalies separately, eliminating the need to compare incoming rules with outgoing rules.
3
Removing policy anomalies locally in each single security device and then adopting rules from a trusted firewall avoids anomalies across distributed devices and preserves policy consistency.
4
The in-out traffic classification can reduce the number of rule comparisons by up to half when detecting policy anomalies.
5
The paper identifies and explains an additional type of policy anomaly that arises under connection-oriented communication protocols.

Access-control/firewall/IPS rules in a single or distributed security devices (classified by incoming vs outgoing traffic)

Detection and removal of policy anomalies and maintenance of policy consistency by classifying rules by in-out traffic direction to reduce comparisons and avoid anomalies across devices; blocking unnecessary traffic and handling anomalies under connection-oriented protocols

Publication Details
Publication Date
2010-01-01
Journal
Publisher
ISSN
Access Type
Author Information
Authors
Sunghyun Kim
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%