{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,28]],"date-time":"2026-07-28T00:37:48Z","timestamp":1785199068750,"version":"3.55.0"},"reference-count":34,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100003407","name":"Ministero dell\u2019Istruzione, dell\u2019Universit\u00e0 e della Ricerca","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003407","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2022,6]]},"DOI":"10.1016\/j.cose.2022.102683","type":"journal-article","created":{"date-parts":[[2022,3,10]],"date-time":"2022-03-10T20:22:50Z","timestamp":1646943770000},"page":"102683","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":7,"special_numbering":"C","title":["Can my firewall system enforce this policy?"],"prefix":"10.1016","volume":"117","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1288-9623","authenticated-orcid":false,"given":"Lorenzo","family":"Ceragioli","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pierpaolo","family":"Degano","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0351-9169","authenticated-orcid":false,"given":"Letterio","family":"Galletta","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2022.102683_bib0001","series-title":"proc. of the 27th IEEE CSF","first-page":"351","article-title":"Mignis: A Semantic Based Tool for Firewall Configuration","author":"Ad\u00e3o","year":"2014"},{"key":"10.1016\/j.cose.2022.102683_bib0002","series-title":"proc. of the 29th IEEE CSF, Lisbon, Portugal, June 27, - July 1","first-page":"194","article-title":"Localizing firewall security policies","author":"Ad\u00e3o","year":"2016"},{"key":"10.1016\/j.cose.2022.102683_bib0003","series-title":"Proceedings of the 41st ACM SIGPLAN-SIGACT Symposium on Principles of Programming Languages","first-page":"113","article-title":"NetKAT: semantic foundations for networks","author":"Anderson","year":"2014"},{"issue":"4","key":"10.1016\/j.cose.2022.102683_bib0004","doi-asserted-by":"crossref","first-page":"381","DOI":"10.1145\/1035582.1035583","article-title":"Firmato: a novel firewall management toolkit","volume":"22","author":"Bartal","year":"2004","journal-title":"ACM Trans. Comput. Syst."},{"issue":"1","key":"10.1016\/j.cose.2022.102683_bib0005","doi-asserted-by":"crossref","first-page":"77","DOI":"10.3233\/JCS-200017","article-title":"FWS: analyzing, maintaining and transcompiling firewalls","volume":"29","author":"Bodei","year":"2021","journal-title":"J. Comput. Secur."},{"key":"10.1016\/j.cose.2022.102683_bib0006","series-title":"Principles of Security and Trust - 7th International Conference, POST 2018","first-page":"303","article-title":"Transcompiling firewalls","volume":"Vol. 10804","author":"Bodei","year":"2018"},{"key":"10.1016\/j.cose.2022.102683_bib0007","series-title":"2018\u00a0IEEE European Symposium on Security and Privacy, EuroS&P 2018","first-page":"92","article-title":"Language-independent synthesis of firewall policies","author":"Bodei","year":"2018"},{"key":"10.1016\/j.cose.2022.102683_bib0008","unstructured":"Capirca \u2014 Multi-platform ACL Generation System., 2021. https:\/\/github.com\/google\/capirca."},{"key":"10.1016\/j.cose.2022.102683_bib0009","series-title":"Proceedings of the 14th ACM SIGSAC Workshop on Programming Languages and Analysis for Security","first-page":"1","article-title":"Are all firewall systems equally powerful?","author":"Ceragioli","year":"2019"},{"key":"10.1016\/j.cose.2022.102683_bib0010","series-title":"The Art of Modelling Computational Systems: A Journey from Logic and Concurrency to Security and Privacy","article-title":"Checking the expressivity of firewall languages","author":"Ceragioli","year":"2019"},{"key":"10.1016\/j.cose.2022.102683_bib0011","series-title":"Proceedings of the Third Italian Conference on Cyber Security, Pisa, Italy, February 13\u201315, 2019.","article-title":"From firewalls to functions and back","author":"Ceragioli","year":"2019"},{"key":"10.1016\/j.cose.2022.102683_bib0012","series-title":"proc. of 2nd IFIP FAST","first-page":"203","article-title":"A Formal Approach to Specify and Deploy a Network Security Policy","author":"Cuppens","year":"2004"},{"key":"10.1016\/j.cose.2022.102683_bib0013","unstructured":"Diekmann, C., 2017. net-network: Public Collection of firewall dumps. https:\/\/github.com\/diekmann\/net-network."},{"issue":"1\u20134","key":"10.1016\/j.cose.2022.102683_bib0014","doi-asserted-by":"crossref","first-page":"191","DOI":"10.1007\/s10817-017-9445-1","article-title":"Verified iptables firewall analysis and verification","volume":"61","author":"Diekmann","year":"2018","journal-title":"J. Autom. Reasoning"},{"key":"10.1016\/j.cose.2022.102683_bib0015","unstructured":"F2F tool., 2021. https:\/\/github.com\/lceragioli\/F2F."},{"key":"10.1016\/j.cose.2022.102683_bib0016","unstructured":"FirewallBuilder., 2000. http:\/\/fwbuilder.sourceforge.net\/."},{"key":"10.1016\/j.cose.2022.102683_bib0017","series-title":"Proceedings of the 3rd IEEE Conference on Communications and Network Security, CNS 2015","first-page":"541","article-title":"A Firewall Algebra for OpenStack","author":"Foley","year":"2015"},{"key":"10.1016\/j.cose.2022.102683_bib0018","series-title":"2017 Formal Methods in Computer Aided Design (FMCAD)","first-page":"220","article-title":"Automated repair by example for firewalls","author":"Hallahan","year":"2017"},{"key":"10.1016\/j.cose.2022.102683_bib0019","unstructured":"How to go from iptables to pf?, 2013. https:\/\/serverfault.com\/questions\/228313\/how-to-go-from-iptables-to-pf."},{"key":"10.1016\/j.cose.2022.102683_bib0020","series-title":"Technical Report","article-title":"Automated Analysis and Debugging of Network Connectivity Policies","author":"Jayaraman","year":"2014"},{"key":"10.1016\/j.cose.2022.102683_bib0021","series-title":"proc. of the 21st IEEE S&P 2000","first-page":"177","article-title":"Fang: A Firewall Analysis Engine","author":"Mayer","year":"2000"},{"key":"10.1016\/j.cose.2022.102683_bib0022","unstructured":"Migrating from iptables to pf, a love story., 2013. http:\/\/daemonforums.org\/showthread.php?t=7775."},{"key":"10.1016\/j.cose.2022.102683_bib0023","series-title":"Proceedings of the 24th Large Installation System Administration Conference, LISA 2010","article-title":"The Margrave Tool for Firewall Analysis","author":"Nelson","year":"2010"},{"key":"10.1016\/j.cose.2022.102683_bib0024","unstructured":"Netfilter., 2019. https:\/\/www.netfilter.org\/."},{"key":"10.1016\/j.cose.2022.102683_bib0025","unstructured":"Packet Filter (PF)., 2019. https:\/\/www.openbsd.org\/faq\/pf\/."},{"key":"10.1016\/j.cose.2022.102683_bib0026","unstructured":"PF - Packet Tagging (Policy Filtering)., 2020. https:\/\/www.openbsd.org\/faq\/pf\/tagging.html."},{"key":"10.1016\/j.cose.2022.102683_bib0027","series-title":"Proceedings of the Workshop on Model-Driven Security Workshop, MDsec 2012","article-title":"A model-driven approach for the extraction of network access-control policies","author":"Perez","year":"2012"},{"key":"10.1016\/j.cose.2022.102683_bib0028","unstructured":"pfSense \u2014 World\u2019s Most Trusted Open Source Firewall., 2021. https:\/\/www.pfsense.org\/."},{"key":"10.1016\/j.cose.2022.102683_bib0029","unstructured":"Queueing to userspace., 2016. https:\/\/wiki.nftables.org\/wiki-nftables\/index.php\/Queueing_to_userspace."},{"key":"10.1016\/j.cose.2022.102683_bib0030","unstructured":"Russell, R., 2002. Linux 2.4 Packet Filtering HOWTO. http:\/\/www.netfilter.org\/documentation\/HOWTO\/packet-filtering-HOWTO.html."},{"key":"10.1016\/j.cose.2022.102683_bib0031","unstructured":"Snort \u2014 Network Intrusion Detection & Prevention System., 2021. https:\/\/www.snort.org\/."},{"key":"10.1016\/j.cose.2022.102683_bib0032","unstructured":"Suricata., 2021. https:\/\/www.suricata.io\/."},{"key":"10.1016\/j.cose.2022.102683_bib0033","unstructured":"The IPFW Firewall., 2017. https:\/\/www.freebsd.org\/doc\/handbook\/firewalls-ipfw.html."},{"key":"10.1016\/j.cose.2022.102683_bib0034","series-title":"Proceedings of the 27th IEEE Symposium on Security and Privacy, S&P 2006","first-page":"199","article-title":"FIREMAN: A Toolkit for FIREwall Modeling and ANalysis","author":"Yuan","year":"2006"}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404822000815?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404822000815?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T19:14:04Z","timestamp":1759086844000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404822000815"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6]]},"references-count":34,"alternative-id":["S0167404822000815"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2022.102683","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2022,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Can my firewall system enforce this policy?","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2022.102683","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2022 Elsevier Ltd. All rights reserved.","name":"copyright","label":"Copyright"}],"article-number":"102683"}}