collaborators

6 papers

cs.NI2017

Provably Secure Networks: Methodology and Toolset for Configuration Management

Cornelius Diekmann

Network administration is an inherently complex task, in particular with regard to security. Using the Isabelle interactive proof assistant, we develop two automated, formally veri…

cs.NI2016

Adaptive Load-Aware Sampling for Network Monitoring on Multicore Commodity Hardware

Lothar Braun, Cornelius Diekmann, Nils Kammenhuber +1

Many current traffic monitoring systems employ deep packet inspection (DPI) in order to analyze network traffic. These systems include intrusion detection systems, software for net…

cs.NI2016

Demonstrating topoS: Theorem-Prover-Based Synthesis of Secure Network Configurations

Cornelius Diekmann, Andreas Korsten, Georg Carle

In network management, when it comes to security breaches, human error constitutes a dominant factor. We present our tool topoS which automatically synthesizes low-level network co…

cs.CR2016

Semantics-Preserving Simplification of Real-World Firewall Rule Sets

Cornelius Diekmann, Lars Hupel, Georg Carle

The security provided by a firewall for a computer network almost completely depends on the rules it enforces. For over a decade, it has been a well-known and unsolved problem that…

cs.CR2016

Verifying Security Policies using Host Attributes

Cornelius Diekmann, Stephan-A. Posselt, Heiko Niedermayer +3

For the formal verification of a network security policy, it is crucial to express the verification goals. These formal goals, called security invariants, should be easy to express…

cs.CR2016

Certifying Spoofing-Protection of Firewalls

Cornelius Diekmann, Lukas Schwaighofer, Georg Carle

We present an algorithm to certify IP spoofing protection of firewall rulesets. The algorithm is machine-verifiably proven sound and its use is demonstrated in real-world scenarios…