Abstract
This paper describes a policy-based approach to firewall management. The Policy-Based Networking (pbn) architecture proposed by the Policy Framework Group of Internet Engineering Task Force (ietf) is analysed, together with the communication protocols, policy specification languages, and the necessary information models.
An overview of policy specification languages applicability topbn architecture is presented paying particular attention to the specification of security policies through Security Policy Specification Language (spsl).
The Common Open Policy Service protocol (cops) and its variant,cops for Policy provisioning (cops-pr), both used for the transport of policy information, are also presented.
The paper continues with a description of an application of thepbn architecture to firewall management. The proposed architecture is presented and its implementation issues are analysed with some usage examples. The paper concludes with the evaluation of the policy-based approach to firewall management.
Résumé
Cet article décrit une méthode de gestion de pare-feux à partir de mise en œuvre de règles. On analyse d’abord l’architecture de réseautique à base de règles (pbn) proposée par le groupe « Policy Framework » de l’ietf qui comporte des protocoles de communication, des langages de spécification de politique et la modélisation de l’information nécessaire. On présente ensuite un état de l’art de l’application des langages de spécification de règles à l’architecturepbn en détaillant particulièrement la spécification des règles de sécurité avec le langagespsl. Le protocolecops et sa variantecops-pr utilisés pour transporter l’information sur les règles sont également présentés. La dernière partie de l’article est consacrée à l’application de l’architecturepbn à la gestion de pare-feux. L’architecture proposée est alors analysée au travers de quelques exemples. L’article se conclut en évaluant l’approche à base de règles dans la gestion des pare-feux.
Similar content being viewed by others
References
Alaetinouglu (C.)et al., Routing Policy Specification Language (rpsl),rfc 2280,ietf, January 1998.
Bergsten (A.),Borg (N.), Implementation and Evaluation of the Common Open Policy Service (cops) Protocol and its use for Policy Provisioning, http://epubl.luth.se/1402-1617/2000/125/, 2000.
Booch (G.)et al., Unified Method for Object-Oriented DevelopmentDocument Set, Rational Software Corporation, 1996, (http://www.rational.com/uml).
Boutaba (R.)et al.,cops-pr with meta-policy support,ietf independent publication, April 2001.
Braden (R.)et al., Resource ReserVation Protocol (rsvp) — Version 1 Functional Specification,rfc 2205,ietf, September 1997.
Bray (T.)et al., eXtensible Markup Language (xml) 1.0,w3c, February 1998, (http://www.w3c.org/tr/rec-xml).
Caldeira (F.),Monteiro (E.), Descrição Geração e Difusão de Políticas de Segurança,in Proceedings ofcrc’2000, November 2000.
Chan (K.)et al.,cops Usage for Policy Provisioning (cops-pr),rfc 3084,ietf, March 2001.
Common Information Model (cim) Specification — Version 2.2,dmtf, June 1999 (http://www.dmtf.org/spec/cim_spec_v22/).
Online manuals (http://www.cisco.com)
Condell (M.)et al., Security Policy Specification Language, Internet draft, draft-ietf-ipsp-spsl-00.text,ietf, March 2000.
Dinesh (V.), Simplifying Network Administration using Policy based Management,ieeeNetwork Magazine, March 2002.
Donnelly (C.),Stallman (R.), Bison — Theyacc-compatible Parser Generator, (http://www.gnu.org/manual/bison/html_mono/bison.html), November 1995.
Durham (D.),Boyle (J.),Cohen (R.),Herzog (S.),Rajan (R.),Sastry (A.), Thecops (Common Open Policy Service) Protocol,rfc 2748, Network Working Group,ietf, January 2000.
Fine (M.)et al., Quality of Service Policy Information Base, Internet draft, draft-mfine-cops-pib-01.txt,ietf, June 1999.
Fine (M.)et al., Framework Policy Information Base, Internet draft, draft-ietf-rap-frameworkpib-04.txt,ietf, November 2000.
Survey on Policy-Based Networking — Addressing Issues, Technological Trends, Future Prospects of Policy Exchange Methods in Multi-Domain Scenarios,intap, 2001, (http://www.net.intap.or.jp/intap/).
Policy Standards andietf Terminology, White paper, Volume #2,iphighway, January 2001.
Kurland (V.),Zaliva (V.). Firewall Builder, (http://www.fwbuilder.org/), 2001
Mahon (H.)et al., Requirements for a Policy Management System, Internet draft, draft-ietf-policy-req-02.txt,ietf, November 1999.
Moore (B.)et al., Policy Core Information Model — Version 1 Specification, Internet draft, draft-ietf-policy-core-info-model-04.txt,ietf March 2000.
Paxson (V.), Flex — A fast scanner generator, (http://www.gnu.org/manual/flex-2.5.4/html_mono/flex.html), March 1995.
Raju (R.)et al., A policy framework for integrated and differentiated services in the internet, inieeeNetwork, September 1999.
Resource Allocation Protocol (rap); (http://www.ietf.org/html.charters/rap-charter.html), 2001.
Darren (R.), Filter language compiler specification (http://coombs.anu.edu.au/~avalon/flc.html), 2001.
Russell (R.), Linuxipchains HowTo, Online, July 2000.
Shepard (S.) Policy-based networks: hype and hope; initProfessional,2, no 1, January 2000.
Simon (R. C.),Ultes-Nitsche (U.), Anxml-based Approach to Modelling and Implementing Firewall Configurations, in proceedings ofissa2002 Information Security conference, Muldersdrift, Gauteng, South Africa, July 2002
Stevens (M.)et al., Policy Framework, Internet draft, draft-ietf-policy-framework-00.txt,ietf, September 1999.
Stone (G.)et al., Network Policy Languages: A Survey and a New Approach, inieeeNetwork, pp. 10–21, January 2001.
Author information
Authors and Affiliations
Corresponding author
Rights and permissions
About this article
Cite this article
Caldeira, F., Monteiro, E. Policy-based networking: applications to firewall management. Ann. Télécommun. 59, 38–54 (2004). https://doi.org/10.1007/BF03179673
Received:
Accepted:
Issue Date:
DOI: https://doi.org/10.1007/BF03179673
Key words
- Networking
- Computer security
- Firewall
- Network architecture
- Specification language
- Transmission protocol
- Decision rule