ČEJKA Rudolf, MATOUŠEK Petr, RÁB Jaroslav, RYŠAVÝ Ondřej and ŠVÉDA Miroslav. A Formal Approach to Network Security Analysis. Brno: Faculty of Information Technology BUT, 2008.
This paper deals with an approach to security analysis of TCP/IP-based computer networks. The method developed stems from a formal model of network topology with changing link states, and deploys bounded model checking of network security properties supported by SAT-based decision procedure. Its implementation consists of a set of tools that provide automatic analysis of router configurations, network topologies, and states with respect to checked properties. While the paper aims at supporting a real practice, its form strives to be exact enough to explain the principles of the method in detail.
