• DocumentCode
    2267747
  • Title

    Parallel Firewall Designs for High-Speed Networks

  • Author

    Fulp, Errin W.

  • Author_Institution
    Dept. of Comput. Sci., Wake Forest Univ., Winston-Salem, NC
  • fYear
    2006
  • fDate
    23-29 April 2006
  • Firstpage
    1
  • Lastpage
    4
  • Abstract
    In a high-speed environment (e.g. Gigabit Ethernet), a single network firewall is a potential bottleneck and increasingly susceptible to denial of service (DoS) attacks. Although creating a faster single firewall is possible, the performance benefits are only temporary as network speeds continue to increase. Therefore new firewall architectures are needed to meet the demands of high-speed networks. This paper reviews different parallel firewall architectures that have the ability to process packets at high speeds. Each design uses an array of firewalls to enforce a security policy, but will differ on how the array is used. Data-parallel distributes arriving packets across the array allowing greater throughput, while function-parallel distributes the rules which reduces processing delay. In general, the parallel designs are more scalable and significantly faster than a traditional single firewall. Simulation will demonstrate the performance benefits of the parallel designs under realistic conditions.
  • Keywords
    authorisation; computer network management; DoS; denial of service; high-speed networks; packets; parallel firewall designs; Access control; Buildings; Computer crime; Computer science; Data security; Delay; Ethernet networks; High-speed networks; Quality of service; Throughput;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM 2006. 25th IEEE International Conference on Computer Communications. Proceedings
  • Conference_Location
    Barcelona
  • ISSN
    0743-166X
  • Print_ISBN
    1-4244-0221-2
  • Type

    conf

  • DOI
    10.1109/INFOCOM.2006.27
  • Filename
    4146680