6 papers
Provably Secure Networks: Methodology and Toolset for Configuration Management
Cornelius Diekmann
Network administration is an inherently complex task, in particular with regard to security. Using the Isabelle interactive proof assistant, we develop two automated, formally veri…
Adaptive Load-Aware Sampling for Network Monitoring on Multicore Commodity Hardware
Lothar Braun, Cornelius Diekmann, Nils Kammenhuber +1
Many current traffic monitoring systems employ deep packet inspection (DPI) in order to analyze network traffic. These systems include intrusion detection systems, software for net…
Demonstrating topoS: Theorem-Prover-Based Synthesis of Secure Network Configurations
Cornelius Diekmann, Andreas Korsten, Georg Carle
In network management, when it comes to security breaches, human error constitutes a dominant factor. We present our tool topoS which automatically synthesizes low-level network co…
Semantics-Preserving Simplification of Real-World Firewall Rule Sets
Cornelius Diekmann, Lars Hupel, Georg Carle
The security provided by a firewall for a computer network almost completely depends on the rules it enforces. For over a decade, it has been a well-known and unsolved problem that…
Verifying Security Policies using Host Attributes
Cornelius Diekmann, Stephan-A. Posselt, Heiko Niedermayer +3
For the formal verification of a network security policy, it is crucial to express the verification goals. These formal goals, called security invariants, should be easy to express…
Certifying Spoofing-Protection of Firewalls
Cornelius Diekmann, Lukas Schwaighofer, Georg Carle
We present an algorithm to certify IP spoofing protection of firewall rulesets. The algorithm is machine-verifiably proven sound and its use is demonstrated in real-world scenarios…