Detail výsledku
SECURITY ANALYSIS OF TCP/IP NETWORKS -- An Approach to Automatic Analysis of Network Security Properties
Ryšavý Ondřej, doc. Ing., Ph.D., UIFS (FIT)
Matoušek Petr, doc. Ing., Ph.D., M.A., UIFS (FIT)
Ráb Jaroslav, Ing., UIFS (FIT)
Čejka Rudolf, Ing., CVT (FIT)
This paper deals with an approach to security analysis of TCP/IP-based computer networks. The method developed stems from a formal model of network topology with changing link states, and deploys bounded model checking of network security properties supported by SAT-based decision procedure. Its implementation consists of a set of tools that provide automatic analysis of router configurations, network topologies, and states with respect to checked properties. While the paper aims at supporting a real practice, its form strives to be exact enough to explain the principles of the method in more detail.
Intranet topology, dynamic routing, state-based reachability, security, bounded model checking, SAT
@inproceedings{BUT34845,
author="Miroslav {Švéda} and Ondřej {Ryšavý} and Petr {Matoušek} and Jaroslav {Ráb} and Rudolf {Čejka}",
title="SECURITY ANALYSIS OF TCP/IP NETWORKS -- An Approach to Automatic Analysis of Network Security Properties",
booktitle="Proceedings of the International Conference on Data Communication Networking ICETE-DCNET 2010",
year="2010",
pages="5--11",
publisher="Institute for Systems and Technologies of Information, Control and Communication",
address="Athens",
isbn="978-989-8425-25-6"
}
Bezpečné, spolehlivé a adaptivní počítačové systémy, VUT, Vnitřní projekty VUT, FIT-S-10-1, zahájení: 2010-03-01, ukončení: 2010-12-31, ukončen
Bezpečnost a zabezpečení aplikací sítí vestavěných systémů, GAČR, Standardní projekty, GA102/08/1429, zahájení: 2008-01-01, ukončení: 2010-12-31, ukončen
Výzkum informačních technologií z hlediska bezpečnosti, MŠMT, Institucionální prostředky SR ČR (např. VZ, VC), MSM0021630528, zahájení: 2007-01-01, ukončení: 2013-12-31, řešení