ForestFirewalls: Getting Firewall Configuration Right in Critical Networks (Technical Report)

02/15/2019
by   Dinesha Ranathunga, et al.
0

Firewall configuration is critical, yet often conducted manually with inevitable errors, leaving networks vulnerable to cyber attack [40]. The impact of misconfigured firewalls can be catastrophic in Supervisory Control and Data Acquisition (SCADA) networks. These networks control the distributed assets of industrial systems such as power generation and water distribution systems. Automation can make designing firewall configurations less tedious and their deployment more reliable. In this paper, we propose ForestFirewalls, a high-level approach to configuring SCADA firewalls. Our goals are three-fold. We aim to: first, decouple implementation details from security policy design by abstracting the former; second, simplify policy design; and third, provide automated checks, pre and post-deployment, to guarantee configuration accuracy. We achieve these goals by automating the implementation of a policy to a network and by auto-validating each stage of the configuration process. We test our approach on a real SCADA network to demonstrate its effectiveness.

READ FULL TEXT
research
09/19/2022

Automated Implementation of Windows-related Security-Configuration Guides

Hardening is the process of configuring IT systems to ensure the securit...
research
11/03/2020

Online Discoverability and Vulnerabilities of ICS/SCADA Devices in the Netherlands

On a regular basis, we read in the news about cyber-attacks on critical ...
research
06/03/2020

Menes: Towards a Generic, Fully-Automated Test and Validation Platform for Wireless Networks

A major step in developing robust wireless systems is to test and valida...
research
04/13/2018

Trustworthy Configuration Management for Networked Devices using Distributed Ledgers

Numerous IoT applications, like building automation or process control o...
research
02/14/2021

An Evolutionary Study of Configuration Design and Implementation in Cloud Systems

Many techniques were proposed for detecting software misconfigurations i...
research
08/12/2021

Automating System Configuration

The increasing complexity of modern configurable systems makes it critic...

Please sign up or login with your details

Forgot password? Click here to reset