Platform-Independent Firewall Policy Representation

Vadim Zaliva
DOI: https://doi.org/10.48550/arXiv.0805.1886
2008-05-14
Abstract:In this paper we will discuss the design of abstract firewall model along with platform-independent policy definition language. We will also discuss the main design challenges and solutions to these challenges, as well as examine several differences in policy semantics between vendors and how it could be mapped to our platform-independent language. We will also touch upon a processing model, describing the mechanism by which an abstract policy could be compiled into a concrete firewall policy syntax. We will discuss briefly some future research directions, such as policy optimization and validation
Cryptography and Security
What problem does this paper attempt to address?