1st IEEE ICNP Workshop on Secure Network Protocols, 2005. (NPSec).
DOI: 10.1109/npsec.2005.1532056
|View full text |Cite
|
Sign up to set email alerts
|

Policy segmentation for intelligent firewall testing

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
22
0

Publication Types

Select...
3
3
3

Relationship

0
9

Authors

Journals

citations
Cited by 29 publications
(22 citation statements)
references
References 6 publications
0
22
0
Order By: Relevance
“…For instance, the test packets can be hand-generated by domain experts to target specific vulnerabilities in the given firewall F , or generated from the formal specifications of the security policy of the given firewall F , as in [6]. A scheme for targeting test packets for better fault coverage is given in [7]. Al-Shaer et al provide a complete framework to generate targeted packets and obtain good coverage in testing in [8].…”
Section: ) Firewall Testingmentioning
confidence: 99%
“…For instance, the test packets can be hand-generated by domain experts to target specific vulnerabilities in the given firewall F , or generated from the formal specifications of the security policy of the given firewall F , as in [6]. A scheme for targeting test packets for better fault coverage is given in [7]. Al-Shaer et al provide a complete framework to generate targeted packets and obtain good coverage in testing in [8].…”
Section: ) Firewall Testingmentioning
confidence: 99%
“…For instance, the test packets can be hand-generated by domain experts to target specific vulnerabilities in the given firewall F , or generated from the formal specifications of the security policy of the given firewall F , as in [3]. A scheme for targeting test packets for better fault coverage is given in [4] and [5]. Blowtorch [6] is a framework to generate packets for testing.…”
Section: Related Workmentioning
confidence: 99%
“…Sets of test input values may be constructed using equivalence class partitioning, intelligent segmentation [11] or expert knowledge. The equivalence class partitioning divides the input domain of policy field into a finite number of partitions or equivalence classes [12].…”
Section: B Test Case Generation For Firewallsmentioning
confidence: 99%
“…The equivalence class partitioning divides the input domain of policy field into a finite number of partitions or equivalence classes [12]. El-Atawy et al [11] proposed intelligent segmentation, where potential erroneous regions in the the firewall input space are adapted using the firewall policy. When determining test input data, values that a hacker might choose may be considered in addition to using the blacklists from network/security administrator or third parties as well as using statistical significant/insignificant past traffic.…”
Section: B Test Case Generation For Firewallsmentioning
confidence: 99%