Strong temporal, weak spatial logic for rule based filters

Villemaire Roger et Hallé Sylvain. (2009). Strong temporal, weak spatial logic for rule based filters. Dans : 16th International Symposium on Temporal Representation and Reasoning , 23-25 July 2009 , Brixen-Bressanone, Italy.

Rule-based filters are sequences of rules formed of a condition and a decision. Rules are applied sequentially up to the first fulfilled condition, whose matching decision determines the outcome. Such filters are particularly useful in network management, where they filter packets allowed to flow in or out of an interface. Properties of filters which either reveal or hint to misconfiguration (anomalies) have been largely studied in the network management community. We show that in fact such properties are of a spatial and temporal nature. Accordingly we introduce a spatio-temporal language appropriate for filter properties, use it to describe major filter anomalies and finally prove that verifying a property in this language can be done in time polynomial in the number of filter rules.

Mots-clés:firewalls, anomalies, temporal logic, spatial logic
