{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2016:KFJIJVWTYB6PORIYWRCYESR7BX","short_pith_number":"pith:KFJIJVWT","canonical_record":{"source":{"id":"1604.00206","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-04-01T11:37:26Z","cross_cats_sorted":["cs.NI"],"title_canon_sha256":"14bb3c97fe14d81b647a729f43d9216a04653481c4fc86d92c56a501575fb71a","abstract_canon_sha256":"ffbd7fa67ecce2f54fa40b236c12dbad5324f1484f94856a888b80eeea86adf9"},"schema_version":"1.0"},"canonical_sha256":"515284d6d3c07cf74518b445824a3f0dd1db67d1e38dd2732c2cfd0bd37b5772","source":{"kind":"arxiv","id":"1604.00206","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1604.00206","created_at":"2026-05-18T01:17:38Z"},{"alias_kind":"arxiv_version","alias_value":"1604.00206v1","created_at":"2026-05-18T01:17:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1604.00206","created_at":"2026-05-18T01:17:38Z"},{"alias_kind":"pith_short_12","alias_value":"KFJIJVWTYB6P","created_at":"2026-05-18T12:30:25Z"},{"alias_kind":"pith_short_16","alias_value":"KFJIJVWTYB6PORIY","created_at":"2026-05-18T12:30:25Z"},{"alias_kind":"pith_short_8","alias_value":"KFJIJVWT","created_at":"2026-05-18T12:30:25Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2016:KFJIJVWTYB6PORIYWRCYESR7BX","target":"record","payload":{"canonical_record":{"source":{"id":"1604.00206","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-04-01T11:37:26Z","cross_cats_sorted":["cs.NI"],"title_canon_sha256":"14bb3c97fe14d81b647a729f43d9216a04653481c4fc86d92c56a501575fb71a","abstract_canon_sha256":"ffbd7fa67ecce2f54fa40b236c12dbad5324f1484f94856a888b80eeea86adf9"},"schema_version":"1.0"},"canonical_sha256":"515284d6d3c07cf74518b445824a3f0dd1db67d1e38dd2732c2cfd0bd37b5772","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T01:17:38.879789Z","signature_b64":"p/Yt15LOjLGI6HqHQpOLSII6IepGXdvPNWk/o3wFTWSVrObqiPGWtnssgeFEmpuedHyHL/nQ+bEabopzr6vTCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"515284d6d3c07cf74518b445824a3f0dd1db67d1e38dd2732c2cfd0bd37b5772","last_reissued_at":"2026-05-18T01:17:38.879188Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T01:17:38.879188Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1604.00206","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:17:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wR5HRoLYaqQJFwWzpk54qr5H1H5t+vqYVF6c2WpzGJHvmuv+nhhnaiDhML9tI0IePu+e7lHSRqY/vgfu0IJdBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-22T04:50:33.888974Z"},"content_sha256":"2fd39875b0a78337cd07640afd8bc83875eeb5ec151ef067ff5a63d4e93853ae","schema_version":"1.0","event_id":"sha256:2fd39875b0a78337cd07640afd8bc83875eeb5ec151ef067ff5a63d4e93853ae"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2016:KFJIJVWTYB6PORIYWRCYESR7BX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Semantics-Preserving Simplification of Real-World Firewall Rule Sets","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.NI"],"primary_cat":"cs.CR","authors_text":"Cornelius Diekmann, Georg Carle, Lars Hupel","submitted_at":"2016-04-01T11:37:26Z","abstract_excerpt":"The security provided by a firewall for a computer network almost completely depends on the rules it enforces. For over a decade, it has been a well-known and unsolved problem that the quality of many firewall rule sets is insufficient. Therefore, there are many tools to analyze them. However, we found that none of the available tools could handle typical, real-world iptables rulesets. This is due to the complex chain model used by iptables, but also to the vast amount of possible match conditions that occur in real-world firewalls, many of which are not understood by academic and open source "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1604.00206","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T01:17:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Ap1DidGQnk+Hz7sNP7PNzREc8hvEIQrNegaDhJM5Mw7Vvagud/805Ahf4C8bC2EScRxWemByx6xtYGJDLXiuAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-22T04:50:33.889330Z"},"content_sha256":"66942c9ff789c65d65ab68cc6afbff47b1de47db98b15ccefd616edbaef3c7ed","schema_version":"1.0","event_id":"sha256:66942c9ff789c65d65ab68cc6afbff47b1de47db98b15ccefd616edbaef3c7ed"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/KFJIJVWTYB6PORIYWRCYESR7BX/bundle.json","state_url":"https://pith.science/pith/KFJIJVWTYB6PORIYWRCYESR7BX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/KFJIJVWTYB6PORIYWRCYESR7BX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-22T04:50:33Z","links":{"resolver":"https://pith.science/pith/KFJIJVWTYB6PORIYWRCYESR7BX","bundle":"https://pith.science/pith/KFJIJVWTYB6PORIYWRCYESR7BX/bundle.json","state":"https://pith.science/pith/KFJIJVWTYB6PORIYWRCYESR7BX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/KFJIJVWTYB6PORIYWRCYESR7BX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2016:KFJIJVWTYB6PORIYWRCYESR7BX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ffbd7fa67ecce2f54fa40b236c12dbad5324f1484f94856a888b80eeea86adf9","cross_cats_sorted":["cs.NI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-04-01T11:37:26Z","title_canon_sha256":"14bb3c97fe14d81b647a729f43d9216a04653481c4fc86d92c56a501575fb71a"},"schema_version":"1.0","source":{"id":"1604.00206","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1604.00206","created_at":"2026-05-18T01:17:38Z"},{"alias_kind":"arxiv_version","alias_value":"1604.00206v1","created_at":"2026-05-18T01:17:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1604.00206","created_at":"2026-05-18T01:17:38Z"},{"alias_kind":"pith_short_12","alias_value":"KFJIJVWTYB6P","created_at":"2026-05-18T12:30:25Z"},{"alias_kind":"pith_short_16","alias_value":"KFJIJVWTYB6PORIY","created_at":"2026-05-18T12:30:25Z"},{"alias_kind":"pith_short_8","alias_value":"KFJIJVWT","created_at":"2026-05-18T12:30:25Z"}],"graph_snapshots":[{"event_id":"sha256:66942c9ff789c65d65ab68cc6afbff47b1de47db98b15ccefd616edbaef3c7ed","target":"graph","created_at":"2026-05-18T01:17:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"The security provided by a firewall for a computer network almost completely depends on the rules it enforces. For over a decade, it has been a well-known and unsolved problem that the quality of many firewall rule sets is insufficient. Therefore, there are many tools to analyze them. However, we found that none of the available tools could handle typical, real-world iptables rulesets. This is due to the complex chain model used by iptables, but also to the vast amount of possible match conditions that occur in real-world firewalls, many of which are not understood by academic and open source ","authors_text":"Cornelius Diekmann, Georg Carle, Lars Hupel","cross_cats":["cs.NI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-04-01T11:37:26Z","title":"Semantics-Preserving Simplification of Real-World Firewall Rule Sets"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1604.00206","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2fd39875b0a78337cd07640afd8bc83875eeb5ec151ef067ff5a63d4e93853ae","target":"record","created_at":"2026-05-18T01:17:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ffbd7fa67ecce2f54fa40b236c12dbad5324f1484f94856a888b80eeea86adf9","cross_cats_sorted":["cs.NI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2016-04-01T11:37:26Z","title_canon_sha256":"14bb3c97fe14d81b647a729f43d9216a04653481c4fc86d92c56a501575fb71a"},"schema_version":"1.0","source":{"id":"1604.00206","kind":"arxiv","version":1}},"canonical_sha256":"515284d6d3c07cf74518b445824a3f0dd1db67d1e38dd2732c2cfd0bd37b5772","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"515284d6d3c07cf74518b445824a3f0dd1db67d1e38dd2732c2cfd0bd37b5772","first_computed_at":"2026-05-18T01:17:38.879188Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T01:17:38.879188Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"p/Yt15LOjLGI6HqHQpOLSII6IepGXdvPNWk/o3wFTWSVrObqiPGWtnssgeFEmpuedHyHL/nQ+bEabopzr6vTCQ==","signature_status":"signed_v1","signed_at":"2026-05-18T01:17:38.879789Z","signed_message":"canonical_sha256_bytes"},"source_id":"1604.00206","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2fd39875b0a78337cd07640afd8bc83875eeb5ec151ef067ff5a63d4e93853ae","sha256:66942c9ff789c65d65ab68cc6afbff47b1de47db98b15ccefd616edbaef3c7ed"],"state_sha256":"609ed0277c59f3ca50e0e95cba57f5ace493ef24c0aeae99009c1c8154f55a00"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aqWMZbhr86L2Rs+ndHfDtcEQm1OlKD5geF9D+8pWqPmwlX3TtBvQrOjtU2Vd0mNuxqmhXxR5p/HD31s7tCeGDw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-22T04:50:33.891215Z","bundle_sha256":"adf42c17f536f57fd3d63578b06da2907d0164c5b1a36b9503016e93df026b47"}}