CA2328012C - Method and apparatus for analyzing one or more firewalls - Google Patents
Method and apparatus for analyzing one or more firewalls Download PDFInfo
- Publication number
- CA2328012C CA2328012C CA002328012A CA2328012A CA2328012C CA 2328012 C CA2328012 C CA 2328012C CA 002328012 A CA002328012 A CA 002328012A CA 2328012 A CA2328012 A CA 2328012A CA 2328012 C CA2328012 C CA 2328012C
- Authority
- CA
- Canada
- Prior art keywords
- gateway
- zone
- network
- query
- graph
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
- 238000000034 method Methods 0.000 title claims abstract description 20
- 238000001914 filtration Methods 0.000 claims abstract description 55
- 230000001131 transforming effect Effects 0.000 claims 3
- 238000012360 testing method Methods 0.000 description 17
- 230000000875 corresponding effect Effects 0.000 description 15
- 230000009471 action Effects 0.000 description 9
- 239000012634 fragment Substances 0.000 description 9
- 238000012546 transfer Methods 0.000 description 4
- 238000013519 translation Methods 0.000 description 3
- 230000003993 interaction Effects 0.000 description 2
- 230000007246 mechanism Effects 0.000 description 2
- 238000012545 processing Methods 0.000 description 2
- 230000001902 propagating effect Effects 0.000 description 2
- 238000013459 approach Methods 0.000 description 1
- 230000000903 blocking effect Effects 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000011156 evaluation Methods 0.000 description 1
- 230000006870 function Effects 0.000 description 1
- 238000013507 mapping Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000005192 partition Methods 0.000 description 1
- 239000000523 sample Substances 0.000 description 1
- 238000000638 solvent extraction Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/14—Network analysis or design
- H04L41/145—Network analysis or design involving simulating, designing, planning or modelling of a network
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/085—Retrieval of network configuration; Tracking network configuration history
- H04L41/0853—Retrieval of network configuration; Tracking network configuration history by actively collecting configuration information or by backing up configuration information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/12—Discovery or management of network topologies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0263—Rule management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- General Business, Economics & Management (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US09/483,876 US7016980B1 (en) | 2000-01-18 | 2000-01-18 | Method and apparatus for analyzing one or more firewalls |
| US09/483,876 | 2000-01-18 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CA2328012A1 CA2328012A1 (en) | 2001-07-18 |
| CA2328012C true CA2328012C (en) | 2007-05-15 |
Family
ID=23921853
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CA002328012A Expired - Lifetime CA2328012C (en) | 2000-01-18 | 2000-12-12 | Method and apparatus for analyzing one or more firewalls |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US7016980B1 (enExample) |
| EP (1) | EP1119151B1 (enExample) |
| JP (1) | JP4658340B2 (enExample) |
| CA (1) | CA2328012C (enExample) |
| DE (1) | DE60111089T2 (enExample) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20200177548A1 (en) * | 2015-11-17 | 2020-06-04 | Zscaler, Inc. | Multi-tenant cloud-based firewall systems and methods |
Families Citing this family (72)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8079086B1 (en) | 1997-11-06 | 2011-12-13 | Finjan, Inc. | Malicious mobile code runtime monitoring system and methods |
| US7058822B2 (en) | 2000-03-30 | 2006-06-06 | Finjan Software, Ltd. | Malicious mobile code runtime monitoring system and methods |
| US9219755B2 (en) | 1996-11-08 | 2015-12-22 | Finjan, Inc. | Malicious mobile code runtime monitoring system and methods |
| CA2296989C (en) | 1999-01-29 | 2005-10-25 | Lucent Technologies Inc. | A method and apparatus for managing a firewall |
| JP4236364B2 (ja) * | 2000-04-04 | 2009-03-11 | 富士通株式会社 | 通信データ中継装置 |
| US7284267B1 (en) * | 2001-03-08 | 2007-10-16 | Mcafee, Inc. | Automatically configuring a computer firewall based on network connection |
| US7150037B2 (en) * | 2001-03-21 | 2006-12-12 | Intelliden, Inc. | Network configuration manager |
| US8135815B2 (en) * | 2001-03-27 | 2012-03-13 | Redseal Systems, Inc. | Method and apparatus for network wide policy-based analysis of configurations of devices |
| JP2003150748A (ja) * | 2001-11-09 | 2003-05-23 | Asgent Inc | リスク評価方法 |
| US20030110379A1 (en) * | 2001-12-07 | 2003-06-12 | Tatu Ylonen | Application gateway system, and method for maintaining security in a packet-switched information network |
| US7953087B1 (en) * | 2001-12-28 | 2011-05-31 | The Directv Group, Inc. | Content filtering using static source routes |
| US8209756B1 (en) | 2002-02-08 | 2012-06-26 | Juniper Networks, Inc. | Compound attack detection in a computer network |
| US7237258B1 (en) | 2002-02-08 | 2007-06-26 | Mcafee, Inc. | System, method and computer program product for a firewall summary interface |
| AUPS214802A0 (en) * | 2002-05-01 | 2002-06-06 | Firebridge Systems Pty Ltd | Firewall with stateful inspection |
| US7036119B1 (en) * | 2002-07-15 | 2006-04-25 | Cisco Technology, Inc. | Method and apparatus for creating a network topograph that includes all select objects that are in a network |
| FI20021407A7 (fi) * | 2002-07-24 | 2004-01-25 | Tycho Tech Oy | Tietoliikenteen suodattaminen |
| US7472421B2 (en) * | 2002-09-30 | 2008-12-30 | Electronic Data Systems Corporation | Computer model of security risks |
| US8407798B1 (en) | 2002-10-01 | 2013-03-26 | Skybox Secutiry Inc. | Method for simulation aided security event management |
| US8359650B2 (en) * | 2002-10-01 | 2013-01-22 | Skybox Secutiry Inc. | System, method and computer readable medium for evaluating potential attacks of worms |
| US6952779B1 (en) * | 2002-10-01 | 2005-10-04 | Gideon Cohen | System and method for risk detection and analysis in a computer network |
| US20050125697A1 (en) * | 2002-12-27 | 2005-06-09 | Fujitsu Limited | Device for checking firewall policy |
| US7188164B1 (en) * | 2003-02-11 | 2007-03-06 | Cyber Operations, Llc | Secure network access control |
| US7447622B2 (en) * | 2003-04-01 | 2008-11-04 | Microsoft Corporation | Flexible network simulation tools and related methods |
| JP3802004B2 (ja) * | 2003-04-18 | 2006-07-26 | 日本電信電話株式会社 | ファイアウォール検査システム、ファイアウォール検査方法、ファイアウォール検査用プログラム、及びファイアウォール検査用記録媒体 |
| US20040223486A1 (en) * | 2003-05-07 | 2004-11-11 | Jan Pachl | Communication path analysis |
| CA2467603A1 (en) * | 2004-05-18 | 2005-11-18 | Ibm Canada Limited - Ibm Canada Limitee | Visualization firewall rules in an auto provisioning environment |
| US8677496B2 (en) * | 2004-07-15 | 2014-03-18 | AlgoSec Systems Ltd. | Method and apparatus for automatic risk assessment of a firewall configuration |
| US20060041936A1 (en) | 2004-08-19 | 2006-02-23 | International Business Machines Corporation | Method and apparatus for graphical presentation of firewall security policy |
| WO2006040812A1 (ja) * | 2004-10-12 | 2006-04-20 | Fujitsu Limited | 運用管理プログラム、運用管理方法および運用管理装置 |
| US20070266431A1 (en) * | 2004-11-04 | 2007-11-15 | Nec Corporation | Firewall Inspecting System and Firewall Information Extraction System |
| US7937755B1 (en) * | 2005-01-27 | 2011-05-03 | Juniper Networks, Inc. | Identification of network policy violations |
| US7797411B1 (en) | 2005-02-02 | 2010-09-14 | Juniper Networks, Inc. | Detection and prevention of encapsulated network attacks using an intermediate device |
| DE102006014793A1 (de) * | 2006-03-29 | 2007-10-04 | Siemens Ag | Sicherheitsanalysator eines Kommunikationsnetzes |
| US8122492B2 (en) | 2006-04-21 | 2012-02-21 | Microsoft Corporation | Integration of social network information and network firewalls |
| US8079073B2 (en) | 2006-05-05 | 2011-12-13 | Microsoft Corporation | Distributed firewall implementation and control |
| US8176157B2 (en) | 2006-05-18 | 2012-05-08 | Microsoft Corporation | Exceptions grouping |
| EP1933519A1 (en) * | 2006-12-12 | 2008-06-18 | Koninklijke KPN N.V. | Streaming media service for mobile telephones |
| US8584227B2 (en) * | 2007-05-09 | 2013-11-12 | Microsoft Corporation | Firewall with policy hints |
| US8839345B2 (en) * | 2008-03-17 | 2014-09-16 | International Business Machines Corporation | Method for discovering a security policy |
| US8060707B2 (en) * | 2008-05-22 | 2011-11-15 | International Business Machines Corporation | Minimization of read response time |
| US9253038B2 (en) * | 2008-08-08 | 2016-02-02 | Hewlett-Packard Development Company, L.P. | End-to-end network access analysis |
| JP5258676B2 (ja) * | 2009-06-12 | 2013-08-07 | Kddi株式会社 | ファイアウォールにおけるルール情報変更方法、管理装置及びプログラム |
| US8018943B1 (en) | 2009-07-31 | 2011-09-13 | Anue Systems, Inc. | Automatic filter overlap processing and related systems and methods |
| US8098677B1 (en) | 2009-07-31 | 2012-01-17 | Anue Systems, Inc. | Superset packet forwarding for overlapping filters and related systems and methods |
| US8934495B1 (en) * | 2009-07-31 | 2015-01-13 | Anue Systems, Inc. | Filtering path view graphical user interfaces and related systems and methods |
| US8955128B1 (en) | 2011-07-27 | 2015-02-10 | Francesco Trama | Systems and methods for selectively regulating network traffic |
| US8930529B1 (en) | 2011-09-27 | 2015-01-06 | Palo Alto Networks, Inc. | Policy enforcement with dynamic address object |
| US9047109B1 (en) | 2012-06-20 | 2015-06-02 | Palo Alto Networks, Inc. | Policy enforcement in virtualized environment |
| US9537891B1 (en) * | 2011-09-27 | 2017-01-03 | Palo Alto Networks, Inc. | Policy enforcement based on dynamically attribute-based matched network objects |
| EP2717516A1 (en) * | 2012-10-04 | 2014-04-09 | Thomson Licensing | Method of protection of data shared between local area network devices and apparatus implementing the method |
| EP2782311A1 (en) * | 2013-03-18 | 2014-09-24 | British Telecommunications public limited company | Methods of testing a firewall, and apparatus therefor |
| US9443075B2 (en) * | 2013-06-27 | 2016-09-13 | The Mitre Corporation | Interception and policy application for malicious communications |
| WO2015066208A1 (en) | 2013-11-04 | 2015-05-07 | Illumio, Inc. | Pairing in a distributed network management system that uses a logical multi-dimensional label-based policy model |
| US9467385B2 (en) | 2014-05-29 | 2016-10-11 | Anue Systems, Inc. | Cloud-based network tool optimizers for server cloud networks |
| US9781044B2 (en) | 2014-07-16 | 2017-10-03 | Anue Systems, Inc. | Automated discovery and forwarding of relevant network traffic with respect to newly connected network tools for network tool optimizers |
| US10050847B2 (en) | 2014-09-30 | 2018-08-14 | Keysight Technologies Singapore (Holdings) Pte Ltd | Selective scanning of network packet traffic using cloud-based virtual machine tool platforms |
| US10419295B1 (en) * | 2014-10-03 | 2019-09-17 | Amdocs Development Limited | System, method, and computer program for automatically generating communication device metadata definitions |
| US11032138B2 (en) * | 2014-10-22 | 2021-06-08 | Level 3 Communications, Llc | Managing traffic control in a network mitigating DDOS |
| US9692727B2 (en) * | 2014-12-02 | 2017-06-27 | Nicira, Inc. | Context-aware distributed firewall |
| JP6476853B2 (ja) * | 2014-12-26 | 2019-03-06 | 富士通株式会社 | ネットワーク監視システム及び方法 |
| US9992134B2 (en) | 2015-05-27 | 2018-06-05 | Keysight Technologies Singapore (Holdings) Pte Ltd | Systems and methods to forward packets not passed by criteria-based filters in packet forwarding systems |
| US10652112B2 (en) | 2015-10-02 | 2020-05-12 | Keysight Technologies Singapore (Sales) Pte. Ltd. | Network traffic pre-classification within VM platforms in virtual processing environments |
| US10116528B2 (en) | 2015-10-02 | 2018-10-30 | Keysight Technologies Singapore (Holdings) Ptd Ltd | Direct network traffic monitoring within VM platforms in virtual processing environments |
| US10142212B2 (en) | 2015-10-26 | 2018-11-27 | Keysight Technologies Singapore (Holdings) Pte Ltd | On demand packet traffic monitoring for network packet communications within virtual processing environments |
| JP2018019207A (ja) * | 2016-07-27 | 2018-02-01 | 富士ゼロックス株式会社 | 連携管理装置及び通信システム |
| US10778722B2 (en) * | 2016-11-08 | 2020-09-15 | Massachusetts Institute Of Technology | Dynamic flow system |
| WO2018094516A1 (en) | 2016-11-25 | 2018-05-31 | Cybernetiq, Inc. | Computer network security configuration visualization and control system |
| US10911403B1 (en) * | 2017-09-25 | 2021-02-02 | Rockwell Collins, Inc. | Systems and methods for secured maintenance gateway |
| US11102072B2 (en) * | 2019-04-19 | 2021-08-24 | Bmc Software, Inc. | Synthetic objects in service models |
| CN111193744B (zh) * | 2019-12-31 | 2022-03-15 | 中信百信银行股份有限公司 | 防火墙策略查询、弹性伸缩方法及系统、设备、存储介质 |
| CN112738032B (zh) * | 2020-12-17 | 2022-10-11 | 公安部第三研究所 | 一种用于防ip欺骗的通讯系统 |
| CN118400193B (zh) * | 2024-06-27 | 2024-09-20 | 武汉思普崚技术有限公司 | 一种网络边界设备的配置检测方法及装置 |
Family Cites Families (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5146560A (en) * | 1988-05-31 | 1992-09-08 | Digital Equipment Corporation | Apparatus for processing bit streams |
| US5490252A (en) * | 1992-09-30 | 1996-02-06 | Bay Networks Group, Inc. | System having central processor for transmitting generic packets to another processor to be altered and transmitting altered packets back to central processor for routing |
| US5898830A (en) * | 1996-10-17 | 1999-04-27 | Network Engineering Software | Firewall providing enhanced network security and user transparency |
| US5726979A (en) | 1996-02-22 | 1998-03-10 | Mci Corporation | Network management system |
| US5845081A (en) | 1996-09-03 | 1998-12-01 | Sun Microsystems, Inc. | Using objects to discover network information about a remote network having a different network protocol |
| US5968176A (en) | 1997-05-29 | 1999-10-19 | 3Com Corporation | Multilayer firewall system |
| US7143438B1 (en) * | 1997-09-12 | 2006-11-28 | Lucent Technologies Inc. | Methods and apparatus for a computer network firewall with multiple domain support |
| US6182226B1 (en) * | 1998-03-18 | 2001-01-30 | Secure Computing Corporation | System and method for controlling interactions between networks |
| US6453419B1 (en) * | 1998-03-18 | 2002-09-17 | Secure Computing Corporation | System and method for implementing a security policy |
| US6298445B1 (en) * | 1998-04-30 | 2001-10-02 | Netect, Ltd. | Computer security |
| CA2296989C (en) * | 1999-01-29 | 2005-10-25 | Lucent Technologies Inc. | A method and apparatus for managing a firewall |
| WO2000078004A2 (en) * | 1999-06-10 | 2000-12-21 | Alcatel Internetworking, Inc. | Policy based network architecture |
-
2000
- 2000-01-18 US US09/483,876 patent/US7016980B1/en not_active Expired - Lifetime
- 2000-12-12 CA CA002328012A patent/CA2328012C/en not_active Expired - Lifetime
-
2001
- 2001-01-08 DE DE60111089T patent/DE60111089T2/de not_active Expired - Lifetime
- 2001-01-08 EP EP01300123A patent/EP1119151B1/en not_active Expired - Lifetime
- 2001-01-18 JP JP2001009751A patent/JP4658340B2/ja not_active Expired - Lifetime
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20200177548A1 (en) * | 2015-11-17 | 2020-06-04 | Zscaler, Inc. | Multi-tenant cloud-based firewall systems and methods |
| US11582192B2 (en) * | 2015-11-17 | 2023-02-14 | Zscaler, Inc. | Multi-tenant cloud-based firewall systems and methods |
Also Published As
| Publication number | Publication date |
|---|---|
| US7016980B1 (en) | 2006-03-21 |
| JP4658340B2 (ja) | 2011-03-23 |
| EP1119151A3 (en) | 2004-01-21 |
| EP1119151A2 (en) | 2001-07-25 |
| DE60111089T2 (de) | 2006-05-04 |
| DE60111089D1 (de) | 2005-07-07 |
| JP2001237895A (ja) | 2001-08-31 |
| EP1119151B1 (en) | 2005-06-01 |
| CA2328012A1 (en) | 2001-07-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CA2328012C (en) | Method and apparatus for analyzing one or more firewalls | |
| Mayer et al. | Offline firewall analysis | |
| US8135815B2 (en) | Method and apparatus for network wide policy-based analysis of configurations of devices | |
| US7003562B2 (en) | Method and apparatus for network wide policy-based analysis of configurations of devices | |
| Bartal et al. | Firmato: A novel firewall management toolkit | |
| Yuan et al. | Fireman: A toolkit for firewall modeling and analysis | |
| US8844041B1 (en) | Detecting network devices and mapping topology using network introspection by collaborating endpoints | |
| US8176561B1 (en) | Assessing network security risk using best practices | |
| US10038671B2 (en) | Facilitating enforcement of security policies by and on behalf of a perimeter network security device by providing enhanced visibility into interior traffic flows | |
| CN100591072C (zh) | 确定通信的允许性及通信中所用的ip协议的方法和系统 | |
| Cuppens et al. | Handling stateful firewall anomalies | |
| US7299489B1 (en) | Method and apparatus for host probing | |
| Marmorstein et al. | A Tool for Automated iptables Firewall Analysis. | |
| Al-Shaer | Automated firewall analytics: Design, configuration and optimization | |
| Khakpour et al. | Quantifying and querying network reachability | |
| De Montigny-Leboeuf et al. | Passive network discovery for real time situation awareness | |
| Khari et al. | Meticulous study of firewall using security detection tools | |
| Marmorstein et al. | An Open Source Solution for Testing NAT'd and Nested iptables Firewalls. | |
| Khakpour et al. | Quarnet: A tool for quantifying static network reachability | |
| Ingham et al. | Network firewalls | |
| CN119835218B (zh) | 跨隔离设备多段网络路径拼接方法 | |
| KR100576711B1 (ko) | 네트워크 보안구조의 지도 구성 방법 | |
| Albanese et al. | Proactive defense through deception | |
| Sveda et al. | Static Analysis of Routing and Firewall Policy Configurations | |
| Chanesh | Using snort network intrusion detection for real-time packet inspection |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| EEER | Examination request | ||
| MKEX | Expiry |
Effective date: 20201214 |