{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T06:44:26Z","timestamp":1764053066582},"reference-count":29,"publisher":"Elsevier BV","issue":"3","license":[{"start":{"date-parts":[[2003,4,1]],"date-time":"2003-04-01T00:00:00Z","timestamp":1049155200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2003,4]]},"DOI":"10.1016\/s0167-4048(03)00310-9","type":"journal-article","created":{"date-parts":[[2003,5,19]],"date-time":"2003-05-19T16:52:26Z","timestamp":1053363146000},"page":"214-232","source":"Crossref","is-referenced-by-count":73,"title":["Analysis of vulnerabilities in Internet firewalls"],"prefix":"10.1016","volume":"22","author":[{"given":"Seny","family":"Kamara","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sonia","family":"Fahmy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Eugene","family":"Schultz","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian","family":"Kerschbaum","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Frantzen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/S0167-4048(03)00310-9_BIB1","doi-asserted-by":"crossref","unstructured":"M. Frantzen, F. Kerschbaum, E. Schultz, and S. Fahmy, 2001. A framework for understanding vulnerabilities in firewalls using a dataflow model of firewall internals. Computers & Security, Vol. 20, No. 3, 2001, pp. 263-270.","DOI":"10.1016\/S0167-4048(01)00314-5"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB2","unstructured":"Ivan Krsul, Software Vulnerability Analysis, Ph.D. thesis, Department of Computer Sciences, Purdue University, 1998, https:\/\/www.cerias.purdue.edu\/techreports-ssl\/public\/98-09.pdf."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB3","unstructured":"W. Du and A.P. Mathur, 2000. Testing for software vulnerability using environment perturbation. Proceeding of the International Conference on Dependable Systems and Networks (DSN 2000), Workshop On Dependability Versus Malicious Faults, June 2000, http:\/\/www.cerias.purdue.edu\/homes\/duw\/research\/paper\/ftcs30workshop.ps, pp. 603-612."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB4","unstructured":"W. Du and A.P. Mathur, 1998. Categorization of software errors that led to security breaches. Proceedings of the 21st National Information Systems Security Conference (NISSC\u201998), 1998, http:\/\/www.cerias.purdue.edu\/homes\/duw\/research\/paper\/nissc98.ps."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB5","doi-asserted-by":"crossref","unstructured":"M. Bishop and D. Bailey, 1996. A critical analysis of vulnerability taxonomies. Proceedings of the NIST Invitational Workshop on Vulnerabilities, July 1996, Also appears as Technical Report 96-11, Department of Computer Science, University of California at Davis (Sept. 1996) at http:\/\/seclab.cs.ucdavis.edu\/projects\/ vulnerabilities\/scriv\/ucd-ecs-96-11.ps. Also see \u201cClassifying Vulnerabilities\u201d, \u201cA Taxonomy of UNIX and Network Security Vulnerabilities\u201d at http:\/\/seclab.cs.ucdavis.edu\/projects\/vulnerabilities\/scriv\/ucd-ecs-95-10.ps and \u201cVulnerabilities Analysis\u201d by the same author.","DOI":"10.21236\/ADA453251"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB6","unstructured":"E. Schultz, 1996. How to perform effective firewall testing. Computer Security Journal, Vol. 12, No. 1, 1996, pp. 47-54."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB7","doi-asserted-by":"crossref","unstructured":"E. Schultz, 1997. When firewalls fail: lessons learned from firewall testing. Network Security, February 1997, pp. 8-11.","DOI":"10.1016\/S1353-4858(97)86649-4"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB8","unstructured":"W.R. Cheswick and S.M. Bellovin, 1994. Firewalls and Internet Security: repelling the wily hacker, Addison-Wesley, Reading, Massachusetts, 1994."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB9","unstructured":"W. Cheswick, 1990. The design of a secure Internet gateway. In: USENIX, Anaheim, CA, USA, June 1990, pp. 233-237."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB10","unstructured":"K. M. Walker and L. Croswhite Cavanaugh, 1998. Computer Security Policies and SunScreen Firewalls, Prentice Hall, Upper Saddle River, New Jersey, 1998."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB11","unstructured":"L. McCarthy, 1998. Intranet Security, Prentice Hall, Upper Saddle River, New Jersey, 1998."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB12","unstructured":"R.C. Summers, 1997. Secure Computing: Threats and Safeguards, McGraw-Hill, 1997."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB13","unstructured":"E. Spafford and S. Garfinkel, 1996. Practical Unix and Internet Security, O\u2019Reilly & Associates, Inc, second edition, 1996."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB14","doi-asserted-by":"crossref","unstructured":"C.L. Schuba, 1997. On the Modeling, Design and Implementation of Firewall Technology, Ph.D. thesis, Department of Computer Sciences, Purdue University, December 1997, https:\/\/www.cerias.purdue.edu\/techreports-ssl\/public\/97-07.pdf","DOI":"10.1109\/CSAC.1997.646183"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB15","doi-asserted-by":"crossref","unstructured":"S. Ioannidis, A. Keromytis, S. Bellovin, and J. Smith, 2000. Implementing a distributed firewall. Proceedings of the ACM CCS, November 2000, Also see http:\/\/www.research.att.com\/smb\/papers\/distfw.html and www.DistributedFirewalls.com.","DOI":"10.1145\/352600.353052"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB16","unstructured":"R.E. Haeni, 1997. Firewall penetration testing, http:\/\/www.seas.gwu.edu\/reto\/papers\/firewall.pdf, 1997."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB17","unstructured":"G. Vigna, A formal model for firewall testing, http:\/\/www2.elet.polimi.it\/pub\/data\/Giovanni.Vigna\/www.docs\/pub\/fwtest.ps.gz."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB18","doi-asserted-by":"crossref","unstructured":"M.R. Lyu and L.K.Y. Lau, 2000. Firewall security: policies, testing and performance evaluation. Proceedings of the COMSAC. IEEE Computer Society, 2000, pp. 116-21.","DOI":"10.1109\/CMPSAC.2000.884700"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB19","doi-asserted-by":"crossref","unstructured":"D. Newman, 1999. Benchmarking terminology for firewall performance, Request for Comments 2647, ftp:\/\/ftp.isi.edu\/in-notes\/rfc2647.txt, August 1999.","DOI":"10.17487\/rfc2647"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB20","doi-asserted-by":"crossref","unstructured":"N. Freed, 2000. Behavior of and requirements for internet firewalls, Request for Comments 2979, http:\/\/search.ietf.org\/rfc\/rfc2979.txt, October 2000.","DOI":"10.17487\/rfc2979"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB21","doi-asserted-by":"crossref","unstructured":"T. Aslam, 1995. A taxonomy of security faults in the UNIX operating system, M.S. thesis, Purdue University, 1995, purdue.edu\/pub\/COAST\/papers\/taimur-aslam\/aslam-taxonomy-msthesis.ps.Z. Also see: Use of a Taxonomy of Security Faults by Taimur Aslam, Ivan Krsul and Gene Spafford.","DOI":"10.1080\/10658989509342510"},{"key":"10.1016\/S0167-4048(03)00310-9_BIB22","unstructured":"\u201cVulnerability databases from the Common Vulnerabilities and Exposures (CVE) and Candidates (CAN),\u201d http:\/\/cve.mitre.org\/cve\/, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB23","unstructured":"\u201cX-Force,\u201d http:\/\/xforce.iss.net\/, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB24","unstructured":"\u201cBugtraq,\u201d http:\/\/www.securityfocus.com\/bugtraq\/archive, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB25","unstructured":"\u201cComputer Emergency Response Team (CERT) advisories,\u201d http:\/\/www.cert.org\/advisories\/, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB26","unstructured":"\u201cSystem Administration, Networking, and Security (SANS),\u201d http:\/\/www.sans.org\/, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB27","unstructured":"\u201cFirewalls digest,\u201d http:\/\/lists.gnac.net\/firewalls\/, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB28","unstructured":"\u201cCheck Point Products,\u201d http:\/\/www.checkpoint.com, 2003."},{"key":"10.1016\/S0167-4048(03)00310-9_BIB29","unstructured":"\u201cSymantec products,\u201d http:\/\/www.symantec.com, 2003."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803003109?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404803003109?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2019,3,21]],"date-time":"2019-03-21T11:50:57Z","timestamp":1553169057000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404803003109"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2003,4]]},"references-count":29,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2003,4]]}},"alternative-id":["S0167404803003109"],"URL":"https:\/\/doi.org\/10.1016\/s0167-4048(03)00310-9","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2003,4]]}}}