【24h】

Firewall Conformance Testing

机译:防火墙一致性测试

获取原文
获取原文并翻译 | 示例

摘要

Firewalls are widely used to protect networks from unauthorised access. To ensure that they implement an organisation's security policy correctly, they need to be tested. We present an approach that addresses this problem. Namely, we show how an organisation's network security policy can be formally specified in a high-level way, and how this specification can be used to automatically generate test cases to test a deployed system. In contrast to other firewall testing methodologies, such as penetration testing, our approach tests conformance to a specified policy. Our test cases are organisation-specific — i.e. they depend on the security requirements and on the network topology of an organisation — and can uncover errors both in the firewall products themselves and in their configuration.
机译:防火墙被广泛用于保护网络免受未经授权的访问。为了确保他们正确实施组织的安全策略,需要对其进行测试。我们提出一种解决此问题的方法。即,我们展示了如何以高级方式正式指定组织的网络安全策略,以及如何使用此规范自动生成测试用例以测试已部署的系统。与其他防火墙测试方法(例如渗透测试)相比,我们的方法测试是否符合指定策略。我们的测试用例是特定于组织的,即它们取决于安全要求和组织的网络拓扑,并且可以发现防火墙产品本身及其配置中的错误。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号