{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T17:54:04Z","timestamp":1754157244520,"version":"3.41.2"},"reference-count":32,"publisher":"Emerald","issue":"4","license":[{"start":{"date-parts":[[2007,8,21]],"date-time":"2007-08-21T00:00:00Z","timestamp":1187654400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.emerald.com\/insight\/site-policies"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2007,8,21]]},"abstract":"<jats:sec><jats:title content-type=\"abstract-heading\">Purpose<\/jats:title><jats:p>The purpose of the paper is to provide a two\u2010tier framework for managing semantic\u2010aware distributed firewall policies to be applied to the devices existing in one administrative domain.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Design\/methodology\/approach<\/jats:title><jats:p>Special attention is paid to the CIM\u2010based information model defined as the ontology to be used in this framework and the AI\u2010based reasoning mechanisms and components used to perform the conflict discovery tasks over the distributed firewall policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Findings<\/jats:title><jats:p>Mechanisms presented allow the solving some of the current issues of the network\u2010centric security model being used in the Internet. The two\u2010tier framework designed provides semantic\u2010aware mechanisms to perform conflict detection and automatic enforcement of policy rules in the distributed firewall scenario. This framework is based on the use of a standard information model and a semantic\u2010aware policy language to formally define (and then process) firewall policies.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Research limitations\/implications<\/jats:title><jats:p>Ongoing work is focused on identifying all kind of conflicts and anomalies that may exist in firewall systems; in parallel to this task a semi\u2010automatic resolver of conflicting policies is currently under design.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Practical implications<\/jats:title><jats:p>Network and security administrators can specify firewall policies and validate them to find syntactic and semantic errors (i.e. policy conflicts). A framework for automated validation and distribution of policies at different levels is included. This ensures that firewall policies produce the desired effects, facilitating the creation and maintenance of firewall rules in one administrative domain.<\/jats:p><\/jats:sec><jats:sec><jats:title content-type=\"abstract-heading\">Originality\/value<\/jats:title><jats:p>A practical and novel two\u2010tier system that provides detection of conflicts in rules existing in a distributed firewall scenario and the automatic and secure deployment of these rules. A packet\u2010filtering model, which is simple and powerful enough for the conflict discovery and rule analysis processes, has been proposed. Moreover, ontology and rule reasoning are being proposed as techniques for the conflict detection problem in this particular scenario.<\/jats:p><\/jats:sec>","DOI":"10.1108\/10662240710828049","type":"journal-article","created":{"date-parts":[[2007,8,18]],"date-time":"2007-08-18T07:01:26Z","timestamp":1187420486000},"page":"362-377","source":"Crossref","is-referenced-by-count":3,"title":["Managing semantic\u2010aware policies in a distributed firewall scenario"],"prefix":"10.1108","volume":"17","author":[{"given":"Gregorio","family":"Mart\u00ednez P\u00e9rez","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"F\u00e9lix J.","family":"Garc\u00eda Clemente","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Antonio F.","family":"G\u00f3mez Skarmeta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"140","reference":[{"key":"key2022012520370458900_b1","doi-asserted-by":"crossref","unstructured":"Al\u2010Shaer, E., Hamed, H., Boutaba, R. and Hasan, M. (2005), \u201cConflict classification and analysis of distributed firewall policies\u201d, IEEE Journal on Selected Areas in Communications (JSAC), Vol. 23 No. 10, pp. 2069\u201084.","DOI":"10.1109\/JSAC.2005.854119"},{"key":"key2022012520370458900_b2","unstructured":"Bellovin, S.M. (1999), \u201cDistributed firewalls\u201d, Login: Magazine, special issue on security."},{"key":"key2022012520370458900_b3","doi-asserted-by":"crossref","unstructured":"Bradshaw, J.M., Uszok, A., Jeffers, R., Suri, N., Hayes, P., Burstein, M., Acquisti, A., Benyo, B. and Breedy, M. (2003), \u201cRepresentation and reasoning for DAML\u2010based policy and domain services in KAoS and Nomads\u201d, Proceedings of the 2nd International Joint Conference on Autonomous Agents & Multi Agent Systems, Melbourne, Australia, July 14\u201018.","DOI":"10.1145\/860575.860709"},{"key":"key2022012520370458900_b4","unstructured":"Distributed Management Task Force, Inc. (2007a), About the DMTF, available at: www.dmtf.org\/about."},{"key":"key2022012520370458900_b5","unstructured":"Distributed Management Task Force, Inc. (2007b), Common Information Model (CIM) Standards, available at: www.dmtf.org\/standards\/cim."},{"key":"key2022012520370458900_b6","unstructured":"Doraswamy, N. and Harkins, D. (2003), IPSec: The New Security Standard for the Internet, Intranets, and Virtual Private Networks, 2nd ed., Prentice Hall, Englewood Cliffs, NJ."},{"key":"key2022012520370458900_b7","unstructured":"Eppstein, D. and Muthukrishnan, S. (2001), \u201cInternet packet filter management and rectangle geometry\u201d, Proceedings of 12th Annual ACM\u2010SIAM Symposium on Discrete Algorithms (SODA), Washington, DC, 7\u20109 January."},{"key":"key2022012520370458900_b8","doi-asserted-by":"crossref","unstructured":"Garc\u00eda Clemente, F.J., Mart\u00ednez P\u00e9rez, G., Bot\u00eda Blaya, J.A. and G\u00f3mez Skarmeta, A.F. (2005), \u201cOn the application of the semantic web rule language in the definition of policies for system security management, paper presented at the OTM 2005, Ayia Napa, Cyprus.","DOI":"10.1007\/11575863_22"},{"key":"key2022012520370458900_b9","doi-asserted-by":"crossref","unstructured":"Garc\u00eda Clemente, F.J., Mart\u00ednez P\u00e9rez, G., Bot\u00eda Blaya, J.A. and G\u00f3mez Skarmeta, A.F. (2006), \u201cDescription of policies enriched by semantics for security management\u201d, in Taniar, D. and Rahayu, J.W. (Eds), Book on Web Semantics and Ontology, Idea Group Inc., Hershey, PA, pp. 362\u201088.","DOI":"10.4018\/978-1-59140-905-2.ch012"},{"key":"key2022012520370458900_b10","doi-asserted-by":"crossref","unstructured":"Gouda, M. and Liu, X. (2004), \u201cFirewall design: consistency, completeness, and compactness\u201d, Proceedings of the 24th IEEE International Conference on Distributed Computing Systems (ICDCS'04), Tokyo, Japan, March 23\u201026.","DOI":"10.1109\/ICDCS.2004.1281597"},{"key":"key2022012520370458900_b11","unstructured":"Guttman, J. (1997), \u201cFiltering posture: local enforcement for global policies\u201d, Proceedings of 1997 IEEE Symposium on security and Privacy, Oakland, CA."},{"key":"key2022012520370458900_b12","doi-asserted-by":"crossref","unstructured":"Harkins, D. and Carrel, D. (1998), The Internet Key Exchange (IKE), RFC 2409, IETF.","DOI":"10.17487\/rfc2409"},{"key":"key2022012520370458900_b13","unstructured":"Hazelhusrt, S. (1999), Algorithms for Analyzing Firewall and Router Access Lists, Technical Report TR\u2010WitsCS\u20101999, Department of Computer Science, University of the Witwatersrand, South Africa."},{"key":"key2022012520370458900_b14","unstructured":"Horrocks, I., Patel\u2010Schneider, P.F., Boley, H., Grosof, B. and Dean, M. (2004), SWRL: A Semantic Web Rule Language Combining OWL and RuleML, W3C, available at: www.w3.org\/Submission\/SWRL\/."},{"key":"key2022012520370458900_b15","unstructured":"HP Labs Semantic Web Research (2007), Jena: A Semantic Web Framework for Java, available at: http:\/\/jena.sourceforge.net\/."},{"key":"key2022012520370458900_b16","doi-asserted-by":"crossref","unstructured":"Ioannidis, S., Keromytis, A., Bellovin, S.M. and Smith, J. (2000), Implementing a Distributed Firewall, Computer and Communications Security (CCS).","DOI":"10.1145\/352600.353052"},{"key":"key2022012520370458900_b17","doi-asserted-by":"crossref","unstructured":"Kent, S. (1991), US DoD Security Options for the Internet Protocol, IETF, RFC 1108.","DOI":"10.17487\/rfc1108"},{"key":"key2022012520370458900_b18","doi-asserted-by":"crossref","unstructured":"Lupu, E. and Sloman, M. (1997), \u201cConflict analysis for management policies\u201d, Proceedings of IFIP\/IEEE International Symposium on Integrated Network Management (IM'1997), May 12\u201016, 1997, San Diego, CA.","DOI":"10.1007\/978-0-387-35180-3_32"},{"key":"key2022012520370458900_b22","unstructured":"McGuinness, D.L. and Harmelen, F. (2004), OWL Web Ontology Language Overview, W3C, available at: www.w3.org\/TR\/owl\u2010features\/."},{"key":"key2022012520370458900_b19","doi-asserted-by":"crossref","unstructured":"Mart\u00ednez P\u00e9rez, G. and G\u00f3mez Skarmeta, A.F. (2004), \u201cPolicy\u2010based dynamic provision of IP services in a secure VPN coalition scenario\u201d, IEEE Communication Magazine, Vol. 42 No. 11, pp. 118\u201024.","DOI":"10.1109\/MCOM.2004.1362554"},{"key":"key2022012520370458900_b20","doi-asserted-by":"crossref","unstructured":"Mart\u00ednez P\u00e9rez, G., G\u00f3mez Skarmeta, A.F., Zeber, S., Spagnolo, J. and Symchych, T. (2006), \u201cDynamic policy\u2010based network management for a secure coalition environment\u201d, IEEE Communication Magazine, Vol. 44 No. 11, pp. 58\u201064.","DOI":"10.1109\/MCOM.2006.248166"},{"key":"key2022012520370458900_b21","doi-asserted-by":"crossref","unstructured":"Mayer, A., Wool, A. and Ziskind, E. (2006), \u201cOffline firewall analysis\u201d, International Journal on Information Security, Vol. 5 No. 3, pp. 125\u201044.","DOI":"10.1007\/s10207-005-0074-z"},{"key":"key2022012520370458900_b23","unstructured":"POSITIF (2007), POSITIF Project Framework, available at: http:\/\/positif.dif.um.es\/."},{"key":"key2022012520370458900_b24","doi-asserted-by":"crossref","unstructured":"Qiu, L., Varghese, G. and Suri, S. (2001), \u201cFast firewall implementations for software and hardware\u2010based routers\u201d, Proceedings of 9th International Conference on Network Protocols (ICNP'2001), 11\u201014 November 2001, Riverside, CA.","DOI":"10.1145\/378420.378849"},{"key":"key2022012520370458900_b25","unstructured":"University of Murcia (2005), UMU\u2010PBNM: University of Murcia Policy\u2010based Network Management Architecture, available at: http:\/\/pbnm.dif.um.es."},{"key":"key2022012520370458900_b26","doi-asserted-by":"crossref","unstructured":"Uribe, T.E. and Cheung, S. (2004), \u201cAutomatic analysis of firewall and network intrusion detection system configurations\u201d, Proceedings of ACM Workshop on Formal Methods in Security Engineering, Washington DC, October 29th.","DOI":"10.1145\/1029133.1029143"},{"key":"key2022012520370458900_b27","unstructured":"Virtual Private Network Consortium (2007), VPNC Member List, available at: www.vpnc.org\/member\u2010list.html."},{"key":"key2022012520370458900_b28","unstructured":"W3C (2007), About the World Wide Web Consortium (W3C), available at: www.w3.org\/Consortium."},{"key":"key2022012520370458900_b29","unstructured":"Woo, T. (2000), \u201cA modular approach to packet classification: algorithms and results\u201d, Proceedings of IEEE INFOCOM'00, Tel Aviv, Israel, March."},{"key":"key2022012520370458900_b30","doi-asserted-by":"crossref","unstructured":"Wool, A. (2004), \u201cA quantitative study of firewall configuration errors\u201d, IEEE Computer, Vol. 37 No. 6, pp. 62\u20107.","DOI":"10.1109\/MC.2004.2"},{"key":"key2022012520370458900_b31","doi-asserted-by":"crossref","unstructured":"Yag\u00fce, M.I., Ma\u00f1a, A. and L\u00f3pez, J. (2005), \u201cA metadata\u2010based access control model for web services\u201d, Internet Research, Vol. 15 No. 1, pp. 99\u2010116.","DOI":"10.1108\/10662240510577095"},{"key":"key2022012520370458900_b32","unstructured":"Yuan, L., Chen, H., Mai, J., Chuah, C., Su, Z. and Mohapatra, P. (2006), \u201cFIREMAN: a toolkit for firewall modeling and analysis\u201d, Proceedings of IEEE Symposium on Security and Privacy (S&P 2006), 21\u201024 May 2006, Berkeley, CA."}],"container-title":["Internet Research"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.emeraldinsight.com\/doi\/full-xml\/10.1108\/10662240710828049","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240710828049\/full\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.emerald.com\/insight\/content\/doi\/10.1108\/10662240710828049\/full\/html","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,24]],"date-time":"2025-07-24T23:40:14Z","timestamp":1753400414000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.emerald.com\/intr\/article\/17\/4\/362-377\/187379"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2007,8,21]]},"references-count":32,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2007,8,21]]}},"alternative-id":["10.1108\/10662240710828049"],"URL":"https:\/\/doi.org\/10.1108\/10662240710828049","relation":{},"ISSN":["1066-2243"],"issn-type":[{"type":"print","value":"1066-2243"}],"subject":[],"published":{"date-parts":[[2007,8,21]]}}}