{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T15:21:01Z","timestamp":1767972061714,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":27,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,11,9]],"date-time":"2020-11-09T00:00:00Z","timestamp":1604880000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EU H2020 Project ASTRID","award":["786922"],"award-info":[{"award-number":["786922"]}]},{"name":"EU H2020 Project CyberSec4Europe","award":["830929"],"award-info":[{"award-number":["830929"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,11,13]]},"DOI":"10.1145\/3411505.3418439","type":"proceedings-article","created":{"date-parts":[[2020,11,2]],"date-time":"2020-11-02T21:07:52Z","timestamp":1604351272000},"page":"25-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Short Paper"],"prefix":"10.1145","author":[{"given":"Daniele","family":"Bringhenti","sequence":"first","affiliation":[{"name":"Politecnico di Torino, Dip. Automatica e Informatica, Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guido","family":"Marchetto","sequence":"additional","affiliation":[{"name":"Politecnico di Torino, Dip. Automatica e Informatica, Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Riccardo","family":"Sisto","sequence":"additional","affiliation":[{"name":"Politecnico di Torino, Dip. Automatica e Informatica, Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fulvio","family":"Valenza","sequence":"additional","affiliation":[{"name":"Politecnico di Torino, Dip. Automatica e Informatica, Torino, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,11,9]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/INM.2009.5188808"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1035582.1035583"},{"key":"e_1_3_2_2_3_1","volume-title":"CRiSIS 2014","author":"Basile Cataldo","year":"2014","unstructured":"Cataldo Basile , Daniele Canavese , Antonio Lioy , and Fulvio Valenza . 2014 . Inter-technology Conflict Analysis for Communication Protection Policies. In Risks and Security of Internet and Systems - 9th International Conference , CRiSIS 2014 , Trento, Italy , August 27-29, 2014, Revised Selected Papers (Lecture Notes in Computer Science, Vol. 8924). Springer, 148--163. https:\/\/doi.org\/10.1007\/978-3-319-17127-2_10 10.1007\/978-3-319-17127-2_10 Cataldo Basile, Daniele Canavese, Antonio Lioy, and Fulvio Valenza. 2014. Inter-technology Conflict Analysis for Communication Protection Policies. In Risks and Security of Internet and Systems - 9th International Conference, CRiSIS 2014, Trento, Italy, August 27-29, 2014, Revised Selected Papers (Lecture Notes in Computer Science, Vol. 8924). Springer, 148--163. https:\/\/doi.org\/10.1007\/978-3-319-17127-2_10"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2019.2895278"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2010.1012.0365"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS47738.2020.9110402"},{"key":"e_1_3_2_2_7_1","volume-title":"Taipei","author":"Chang Chi-Lan","year":"2005","unstructured":"Chi-Lan Chang , Yun-Peng Chiu , and Chin-Laung Lei . 2005 . Automatic Generation of Conflict-Free IPsec Policies. In Formal Techniques for Networked and Distributed Systems - FORTE 2005, 25th IFIP WG 6.1 International Conference , Taipei , Taiwan, October 2-5, 2005, Proceedings. 233--246. https:\/\/doi.org\/10.1007\/11562436_18 10.1007\/11562436_18 Chi-Lan Chang, Yun-Peng Chiu, and Chin-Laung Lei. 2005. Automatic Generation of Conflict-Free IPsec Policies. In Formal Techniques for Networked and Distributed Systems - FORTE 2005, 25th IFIP WG 6.1 International Conference, Taipei, Taiwan, October 2-5, 2005, Proceedings. 233--246. https:\/\/doi.org\/10.1007\/11562436_18"},{"key":"e_1_3_2_2_8_1","volume-title":"CAV 2017, Heidelberg, Germany, July 24-28, 2017, Proceedings, Part II. 261--281","author":"El-Hassany Ahmed","unstructured":"Ahmed El-Hassany , Petar Tsankov , Laurent Vanbever , and Martin T. Vechev . 2017. Network-Wide Configuration Synthesis. In Computer Aided Verification - 29th International Conference , CAV 2017, Heidelberg, Germany, July 24-28, 2017, Proceedings, Part II. 261--281 . https:\/\/doi.org\/10.1007\/978-3-319-63390-9_14 10.1007\/978-3-319-63390-9_14 Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, and Martin T. Vechev. 2017. Network-Wide Configuration Synthesis. In Computer Aided Verification - 29th International Conference, CAV 2017, Heidelberg, Germany, July 24-28, 2017, Proceedings, Part II. 261--281. https:\/\/doi.org\/10.1007\/978-3-319-63390-9_14"},{"key":"e_1_3_2_2_9_1","volume-title":"NetComplete: Practical Network-Wide Configuration Synthesis with Autocompletion. In 15th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2018","author":"El-Hassany Ahmed","year":"2018","unstructured":"Ahmed El-Hassany , Petar Tsankov , Laurent Vanbever , and Martin T. Vechev . 2018 . NetComplete: Practical Network-Wide Configuration Synthesis with Autocompletion. In 15th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2018 , Renton, WA, USA , April 9-11, 2018 . 579--594. https:\/\/www.usenix.org\/conference\/nsdi18\/presentation\/el-hassany Ahmed El-Hassany, Petar Tsankov, Laurent Vanbever, and Martin T. Vechev. 2018. NetComplete: Practical Network-Wide Configuration Synthesis with Autocompletion. In 15th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2018, Renton, WA, USA, April 9-11, 2018. 579--594. https:\/\/www.usenix.org\/conference\/nsdi18\/presentation\/el-hassany"},{"key":"e_1_3_2_2_10_1","volume-title":"12th International Workshop on Distributed Systems, DSOM 2001, Nancy, France, October 15-17, 2001. Proceedings. 279--290","author":"Fu Zhi","year":"2001","unstructured":"Zhi Fu and Shyhtsun Felix Wu . 2001 . Automatic Generation of IPSec\/VPN Security Policies In an Intra-Domain Environment. In Operations & Management , 12th International Workshop on Distributed Systems, DSOM 2001, Nancy, France, October 15-17, 2001. Proceedings. 279--290 . Zhi Fu and Shyhtsun Felix Wu. 2001. Automatic Generation of IPSec\/VPN Security Policies In an Intra-Domain Environment. In Operations & Management, 12th International Workshop on Distributed Systems, DSOM 2001, Nancy, France, October 15-17, 2001. Proceedings. 279--290."},{"key":"e_1_3_2_2_11_1","volume-title":"DPM 2010 and 3rd International Workshop, SETOP 2010","author":"Garc\u00eda-Alfaro Joaqu\u00edn","year":"2010","unstructured":"Joaqu\u00edn Garc\u00eda-Alfaro , Fr\u00e9d\u00e9 ric Cuppens , Nora Cuppens-Boulahia , and Stere Preda . 2010 . MIRAGE: A Management Tool for the Analysis and Deployment of Network Security Policies. In Data Privacy Management and Autonomous Spontaneous Security - 5th International Workshop , DPM 2010 and 3rd International Workshop, SETOP 2010 , Athens, Greece , September 23, 2010, Revised Selected Papers. 203--215. https:\/\/doi.org\/10.1007\/978-3-642-19348-4_15 10.1007\/978-3-642-19348-4_15 Joaqu\u00edn Garc\u00eda-Alfaro, Fr\u00e9d\u00e9 ric Cuppens, Nora Cuppens-Boulahia, and Stere Preda. 2010. MIRAGE: A Management Tool for the Analysis and Deployment of Network Security Policies. In Data Privacy Management and Autonomous Spontaneous Security - 5th International Workshop, DPM 2010 and 3rd International Workshop, SETOP 2010, Athens, Greece, September 23, 2010, Revised Selected Papers. 203--215. https:\/\/doi.org\/10.1007\/978-3-642-19348-4_15"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-009-9147-0"},{"key":"e_1_3_2_2_13_1","volume-title":"Filtering Postures: Local Enforcement for Global Policies. In 1997 IEEE Symposium on Security and Privacy","author":"Guttman Joshua D.","year":"1997","unstructured":"Joshua D. Guttman . 1997 . Filtering Postures: Local Enforcement for Global Policies. In 1997 IEEE Symposium on Security and Privacy , May 4-7, 1997, Oakland, CA, USA. 120--129. https:\/\/doi.org\/10.1109\/SECPRI. 1997.601327 10.1109\/SECPRI.1997.601327 Joshua D. Guttman. 1997. Filtering Postures: Local Enforcement for Global Policies. In 1997 IEEE Symposium on Security and Privacy, May 4-7, 1997, Oakland, CA, USA. 120--129. https:\/\/doi.org\/10.1109\/SECPRI.1997.601327"},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-004-0052-x"},{"key":"e_1_3_2_2_15_1","volume-title":"Modeling and Verification of IPSec and VPN Security Policies. In 13th IEEE International Conference on Network Protocols (ICNP 2005)","author":"Hamed Hazem H.","year":"2005","unstructured":"Hazem H. Hamed , Ehab S. Al-Shaer , and Will Marrero . 2005 . Modeling and Verification of IPSec and VPN Security Policies. In 13th IEEE International Conference on Network Protocols (ICNP 2005) , 6-9 November 2005, Boston, MA, USA. 259--278. https:\/\/doi.org\/10.1109\/ICNP. 2005.25 10.1109\/ICNP.2005.25 Hazem H. Hamed, Ehab S. Al-Shaer, and Will Marrero. 2005. Modeling and Verification of IPSec and VPN Security Policies. In 13th IEEE International Conference on Network Protocols (ICNP 2005), 6-9 November 2005, Boston, MA, USA. 259--278. https:\/\/doi.org\/10.1109\/ICNP.2005.25"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.2017.1500803CM"},{"key":"e_1_3_2_2_17_1","volume-title":"Policy Based ACL Configuration Synthesis in Enterprise Networks: A Formal Approach. In International Symposium on Electronic System Design, ISEDs 2012","author":"Maity Soumya","year":"2012","unstructured":"Soumya Maity , Padmalochan Bera , and S. K. Ghosh . 2012 . Policy Based ACL Configuration Synthesis in Enterprise Networks: A Formal Approach. In International Symposium on Electronic System Design, ISEDs 2012 , Kolkata, India, December 19--22 , 2012 . 314--318. https:\/\/doi.org\/10.1109\/ISED.2012.72 10.1109\/ISED.2012.72 Soumya Maity, Padmalochan Bera, and S. K. Ghosh. 2012. Policy Based ACL Configuration Synthesis in Enterprise Networks: A Formal Approach. In International Symposium on Electronic System Design, ISEDs 2012, Kolkata, India, December 19--22, 2012. 314--318. https:\/\/doi.org\/10.1109\/ISED.2012.72"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2015.2477041"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3287306"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.5220\/0005946201970206"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-010-9168-7"},{"key":"e_1_3_2_2_22_1","volume-title":"Security Policy Enforcement Through Refinement Process. In 7th International Conference of B Users, Besancc on, France, January 17--19, 2007, Proceedings. 216--231","author":"Stouls Nicolas","year":"2007","unstructured":"Nicolas Stouls and Marie-Laure Potet . 2007 . Security Policy Enforcement Through Refinement Process. In 7th International Conference of B Users, Besancc on, France, January 17--19, 2007, Proceedings. 216--231 . https:\/\/doi.org\/10.1007\/11955757_18 10.1007\/11955757_18 Nicolas Stouls and Marie-Laure Potet. 2007. Security Policy Enforcement Through Refinement Process. In 7th International Conference of B Users, Besancc on, France, January 17--19, 2007, Proceedings. 216--231. https:\/\/doi.org\/10.1007\/11955757_18"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2017.2708096"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"crossref","unstructured":"Verizon. 2020. 2020 Data Breach Investigations Report.  Verizon. 2020. 2020 Data Breach Investigations Report.","DOI":"10.1016\/S1361-3723(20)30059-2"},{"key":"e_1_3_2_2_25_1","volume-title":"FACE: A Firewall Analysis and Configuration Engine. In 2005 IEEE\/IPSJ International Symposium on Applications and the Internet (SAINT 2005","author":"Verma Pavan","year":"2005","unstructured":"Pavan Verma and Atul Prakash . 2005 . FACE: A Firewall Analysis and Configuration Engine. In 2005 IEEE\/IPSJ International Symposium on Applications and the Internet (SAINT 2005 ), 31 January - 4 February 2005, Trento, Italy. 74--81. https:\/\/doi.org\/10.1109\/SAINT.2005.28 10.1109\/SAINT.2005.28 Pavan Verma and Atul Prakash. 2005. FACE: A Firewall Analysis and Configuration Engine. In 2005 IEEE\/IPSJ International Symposium on Applications and the Internet (SAINT 2005), 31 January - 4 February 2005, Trento, Italy. 74--81. https:\/\/doi.org\/10.1109\/SAINT.2005.28"},{"key":"e_1_3_2_2_26_1","volume-title":"BANDS: An Inter-domain Internet Security Policy Management System for IPSec\/VPN. In IFIP\/IEEE Eighth International Symposium on Integrated Network Management (IM 2003)","author":"Yang Yanyan","year":"2003","unstructured":"Yanyan Yang , Zhi (Judy) Fu , and Shyhtsun Felix Wu . 2003 . BANDS: An Inter-domain Internet Security Policy Management System for IPSec\/VPN. In IFIP\/IEEE Eighth International Symposium on Integrated Network Management (IM 2003) , March 24-28, 2003, Colorado Springs, USA. 231--244. Yanyan Yang, Zhi (Judy) Fu, and Shyhtsun Felix Wu. 2003. BANDS: An Inter-domain Internet Security Policy Management System for IPSec\/VPN. In IFIP\/IEEE Eighth International Symposium on Integrated Network Management (IM 2003), March 24-28, 2003, Colorado Springs, USA. 231--244."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2004.1317665"}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2nd Workshop on Cyber-Security Arms Race"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3411505.3418439","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3411505.3418439","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:37Z","timestamp":1750197757000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3411505.3418439"}},"subtitle":["Automatic Configuration for an Optimal Channel Protection in Virtualized Networks"],"short-title":[],"issued":{"date-parts":[[2020,11,9]]},"references-count":27,"alternative-id":["10.1145\/3411505.3418439","10.1145\/3411505"],"URL":"https:\/\/doi.org\/10.1145\/3411505.3418439","relation":{},"subject":[],"published":{"date-parts":[[2020,11,9]]},"assertion":[{"value":"2020-11-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}