CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-14
shaunm shaunm is offline
Junior Member
 
Join Date: 2007-09-10
Location: New Hampshire
Posts: 2
Rep Power: 0
shaunm has an average reputation (10+)
Send a message via AIM to shaunm
Default Firewall rules and problems for visualization research

Hello all,

I am looking for old or unusual firewall files that could be published for use in my part-time study for a doctorate in Computer Science. Barry Stiefel suggested that the members might have some data to contribute.

My research involves applying multi-dimensional information visualization techniques to the comprehension and management of firewall rulesets. My adviser is Professor Georges Grinstein of the Institute for Visualization and Perception Research, Computer Science Dept., Univ. of Massachusetts/Lowell.

There is no prior published work on this particular topic. My initial surveys of the field suggest that the primary approach to editing rulesets are essentially based on text-editing capabilities (from the info visualization perspective, a spreadsheet-like table with visual symbols for services or accept/deny is essentially a text-editor).

That drives me nuts. The human visual cortex is one of the most powerful and massively parallel processing setups in nature, and the highest bandwidth channel into the human brain. Using a text representation is the lowest efficiency use of that channel. I want to change that so that people can look at a firewall (well, a representation of a firewall) and go "Yes, that's it!" or "What the heck is that?" in very short time frames (seconds and minutes, not hours).

Given the state of research effort to date, the research is in a very early or immature stage, dealing with highly limited/abstracted forms of firewalls. Specifically, firewall rules are treated as objects (six-tuples) that compare packet header fields to an interval in each of five dimensions and when a match is achieved, the corresponding action is taken. (note that in the abstracted research version of rulesets that I am working with, the distinction between a dynamic packet firewall and a router with an access control list essentially disappears).

The five dimensions are:
source address;
destination address;
source port;
destination port; and
protocol number.

At this point, the rules are stateless, making no use of historical information regarding packet flows. This is admittedly a very primitive view of firewalls/ACLs, but one solves the simpler problems first. In this case, a five or six dimensional visualization problem.

This view of firewalls is very primitive compared to what a user currently sees at the administrator end of a Checkpoint-1 firewall. Nonetheless, proposed visual approaches must meet the needs of a user community.

You are, collectively, a community of users. I am soliciting the community for:

1)Examples of real firewall rulesets that could be published (perhaps because the organization no longer exists, or has completely reconfigured its topology and connectedness).

2) Examples of specific debugging incidents where an obscure or non-obvious rule, or an unintended interaction between rules, created a problem.

3) Educational examples of how to meet more complex configuration and protection goals.


My purpose is to use this material to summarize user tasks and concerns. In turn, user tasks and concerns act as a basis for building visualizations that might transform the task of configuring firewalls.

So what have you got that is unusual, obnoxious, or difficult? And that we can find a way to anonymize enough so you will be comfortable if it is published?


Shaun P. Morrissey
smorriss (at) cs.uml.edu
__________________
"Discovery consists of seeing what everybody has seen,
and thinking what nobody has thought."
Albert Szent-Gyorgi
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:39.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0