Αυτοματοποίηση πολίτικων δικτυακής ασφάλειας σε ΜΜΕς
Automating network security policies for SMEs

View/ Open
Abstract
This thesis focuses on the design and automation of firewall policies for small and medium-sized enterprises (SMEs), aiming to enhance network security while reducing the complexity associated with firewall rule management. SMEs often face limitations in technical expertise and available resources, which makes the correct implementation and maintenance of security policies particularly challenging.
Within the scope of this work, a practical automation framework based on the pfSense firewall is proposed, enabling the creation and deployment of firewall rules through structured Excel files. The framework utilizes predefined lists, aliases, and data validation mechanisms in order to minimize configuration errors and ensure consistency across security policies.
The implementation was carried out in a controlled laboratory environment using virtualization technologies (Proxmox), while additional security mechanisms, such as pfBlockerNG and the Suricata intrusion detection and prevention system (IDS/IPS), were integrated to strengthen overall protection. Finally, functional tests were conducted to verify the correct application of firewall rules, and the effectiveness of the proposed approach was evaluated in the context of a typical SME environment, considering fundamental principles of the ISO/IEC 27001 standard.


