19th Annual Computer Security Applications Conference (ACSAC '03)
A Multi-View Tool for Checking the Security Semantics of Router Configurations
Las Vegas, Nevada
December 08-December 12
ISBN: 0-7692-2041-3
Routers are critical components of IP networks, but hardly any tool support for analyzing their security exists to date. We have developed such a tool, named CROCODILE, that tracks the security implications of related configuration directives that may be scattered all over the router's configuration, instead of analyzing only isolated configuration clauses like other tools do. Our tool offers several novel evaluation capabilities and presents its findings as a collection of multi-view displays, enabling the user to focus on selected aspects, and to navigate deeper and deeper into specific details. We demonstrate the practical use of CROCODILE, and a comparison with the well-known RAT tool illustrates CROCODILE's remarkable capabilities.