Towards network security policy generation for configuration analysis and testing

  • Authors:
  • Taghrid Samak;Adel El-Atawy;Ehab Al-Shaer

  • Affiliations:
  • DePaul University, Chicago, IL, USA;DePaul University, Chicago, IL, USA;DePaul University, Chicago, IL, USA

  • Venue:
  • Proceedings of the 2nd ACM workshop on Assurable and usable security configuration
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Access-control lists are an essential part in the security framework of any system. Researchers are always in need to have a repository of ready made policies for conducting research and development. Such policies, especially firewall policies which are the focus of our work, are needed to perform performance testing as well as configuration analysis. In this paper we introduce a novel technique to perform access-control policy generation. The proposed approach learns policy parameters from a set of given policies. It generates policies that conform with natural policy-writing practices while following the grammar syntax required by the security device. A probabilistic learning approach is used to infer transition probabilities for the given policy grammar.