DocumentCode :
1828847
Title :
Performance Evaluation of Widely Used Portknoking Algorithms
Author :
Khan, Z.A. ; Javaid, N. ; Arshad, M.H. ; Bibi, A. ; Qasim, B.
Author_Institution :
Dept. of Electr. Eng., COMSATS Inst. of Inf. Technol., Islamabad, Pakistan
fYear :
2012
fDate :
25-27 June 2012
Firstpage :
903
Lastpage :
907
Abstract :
Port knocking is a technique by which only a single packet or special sequence will permit the firewall to open a port on a machine where all ports are blocked by default. It is a passive authorization technique which offers firewall-level authentication to ensure authorized access to potentially vulnerable network services. In this paper, we present performance evaluation and analytical comparison of three widely used port knocking (PK) algorithms, Aldaba, FWKNOP and SIG-2. Comparative analysis is based upon ten selected parameters; Platforms (Supported OS), Implementation (PK, SPA or both), Protocols (UDP, TCP, ICMP), Out of Order packet delivery, NAT (Network Address Translation), Encryption Algorithms, Root privileges (For installation and operation), Weak Passwords, Replay Attacks and IPv6 compatibility. Based upon these parameters, relative performance score has been given to each algorithm. Finally, we deduce that FWKNOP due to compatibility with windows client is the most efficient among chosen PK implementations.
Keywords :
IP networks; authorisation; computer network performance evaluation; transport protocols; Aldaba; FWKNOP; ICMP protocol; IPv6 compatibility; NAT; OS; PK algorithms; SIG-2; SPA; TCP protocol; UDP protocol; authorized access; encryption algorithms; firewall-level authentication; network address translation; network services; order packet delivery; passive authorization technique; passwords; performance evaluation; port knoking algorithms; replay attacks; root privileges; windows client; Authentication; Authorization; IP networks; Protocols; Servers; Authenticating User; Firewall knock operator; Internet Protocol; Man In the Middle; Network Address Translator; Port Knocking; Secure Shell; Single Packet Authorization; Transmission Control Protocol; User Datagram Protocol;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
High Performance Computing and Communication & 2012 IEEE 9th International Conference on Embedded Software and Systems (HPCC-ICESS), 2012 IEEE 14th International Conference on
Conference_Location :
Liverpool
Print_ISBN :
978-1-4673-2164-8
Type :
conf
DOI :
10.1109/HPCC.2012.129
Filename :
6332267
Link To Document :
بازگشت