Are All Firewall Systems Equally Powerful?

被引:2
|
作者
Ceragioli, Lorenzo [1 ]
Degano, Pierpaolo [1 ]
Galletta, Letterio [2 ]
机构
[1] Univ Pisa, Dipartimento Informat, Pisa, Italy
[2] IMT Sch Adv Studies, Lucca, Italy
关键词
Firewall configuration languages; Firewall semantics; Configuration analysis and porting;
D O I
10.1145/3338504.3357340
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls are a fundamental tool for managing and protecting computer networks. They not only permit specifying which packets are allowed to enter a network, but also how these packets are modified by translating IP addresses and performing port redirection (NAT). Many firewalls systems are available which provide different tools and configuration languages. In contrast with the intuition, the most widespread languages cannot express the same configurations, even when simple filtering and NAT transformations are considered. This paper formally investigates the power of firewall languages of the most used tools in Unix and Linux. In particular, we introduce two kinds of expressivity. The first concerns the ways a packet can be transformed by NAT. According to this criterion iptables is strictly more expressive than ipfw and pf that are equivalent. The second kind is more finer-grained and considers the dependencies among the management of all packets. Our results show that some configurations are expressible in a system, but not in another one. Indeed, iptables is incomparable with the others, and ipfw is more expressive than pf.
引用
收藏
页码:1 / +
页数:17
相关论文
共 50 条
  • [31] Are all monitoring boundaries equally ethical?
    Ellenberg, SS
    [J]. CONTROLLED CLINICAL TRIALS, 2003, 24 (05): : 585 - 588
  • [32] Not all group incentives are created equally
    Salk, Carl
    Travers, Henry
    [J]. CONSERVATION LETTERS, 2018, 11 (01):
  • [33] Not all trade restrictions are created equally
    Cole, Matthew T.
    [J]. REVIEW OF WORLD ECONOMICS, 2011, 147 (03) : 411 - 427
  • [34] All Liver Cysts Are Not Created Equally
    Leverage, Scott
    Jain, Arpana
    Ganesh, Halemane
    Gedaly, Roberto
    Pawa, Rishi
    [J]. AMERICAN JOURNAL OF GASTROENTEROLOGY, 2010, 105 : S285 - S286
  • [35] Lacunar syndromes: Are they all equally benign?
    Narasimhalu, Kaavya
    Woon, Fung Peng
    Ng, Szu Chyi
    De Silva, Deidre Anne
    [J]. NEUROLOGY AND CLINICAL NEUROSCIENCE, 2020, 8 (02): : 55 - 60
  • [36] NOT ALL FIRST SEIZURES ARE CREATED EQUALLY
    Sirven, Joseph I.
    [J]. EPILEPSY CURRENTS, 2009, 9 (06) : 164 - 165
  • [37] Not of all P waves are equally created
    Qian, Xiaoxiao
    Sandesara, Chirag
    [J]. EUROPEAN HEART JOURNAL-CASE REPORTS, 2022, 6 (05)
  • [38] Not all narrative shifts function equally
    Rich, SS
    Taylor, HA
    [J]. MEMORY & COGNITION, 2000, 28 (07) : 1257 - 1266
  • [39] ALL-POWERFUL - OR ALL TOO MUCH
    ANDERSON, J
    [J]. ELECTRONICS WORLD & WIRELESS WORLD, 1992, (1679): : 824 - 826
  • [40] FileWall: A firewall for network file systems
    Smaldone, Stephen
    Bohra, Aniruddha
    Iftode, Liviu
    [J]. DASC 2007: THIRD IEEE INTERNATIONAL SYMPOSIUM ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, PROCEEDINGS, 2007, : 153 - +