Iptables Semantics (Q7361641)

From MaRDI portal

!

This is the item page for this Wikibase entity, intended for internal use and editing purposes. Please use the normal view instead:

AFP entry Iptables_Semantics
Language Label Description Also known as
default for all languages
No label defined
    English
    Iptables Semantics
    AFP entry Iptables_Semantics

      Statements

      9 September 2016
      0 references
      Cornelius Diekmann
      0 references
      Lars Hupel
      0 references
      Iptables Semantics (English)
      0 references
      We present a big step semantics of the filtering behavior of the Linux/netfilter iptables firewall. We provide algorithms to simplify complex iptables rulests to a simple firewall model (c.f. AFP entry Simple_Firewall ) and to verify spoofing protection of a ruleset. Internally, we embed our semantics into ternary logic, ultimately supporting every iptables match condition by abstracting over unknowns. Using this AFP entry and all entries it depends on, we created an easy-to-use, stand-alone haskell tool called fffuu . The tool does not require any input —except for the iptables-save dump of the analyzed firewall— and presents interesting results about the user's ruleset. Real-Word firewall errors have been uncovered, and the correctness of rulesets has been proved, with the help of our tool.
      0 references
      0 references
      0 references