DocumentCode :
2267747
Title :
Parallel Firewall Designs for High-Speed Networks
Author :
Fulp, Errin W.
Author_Institution :
Dept. of Comput. Sci., Wake Forest Univ., Winston-Salem, NC
fYear :
2006
fDate :
23-29 April 2006
Firstpage :
1
Lastpage :
4
Abstract :
In a high-speed environment (e.g. Gigabit Ethernet), a single network firewall is a potential bottleneck and increasingly susceptible to denial of service (DoS) attacks. Although creating a faster single firewall is possible, the performance benefits are only temporary as network speeds continue to increase. Therefore new firewall architectures are needed to meet the demands of high-speed networks. This paper reviews different parallel firewall architectures that have the ability to process packets at high speeds. Each design uses an array of firewalls to enforce a security policy, but will differ on how the array is used. Data-parallel distributes arriving packets across the array allowing greater throughput, while function-parallel distributes the rules which reduces processing delay. In general, the parallel designs are more scalable and significantly faster than a traditional single firewall. Simulation will demonstrate the performance benefits of the parallel designs under realistic conditions.
Keywords :
authorisation; computer network management; DoS; denial of service; high-speed networks; packets; parallel firewall designs; Access control; Buildings; Computer crime; Computer science; Data security; Delay; Ethernet networks; High-speed networks; Quality of service; Throughput;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM 2006. 25th IEEE International Conference on Computer Communications. Proceedings
Conference_Location :
Barcelona
ISSN :
0743-166X
Print_ISBN :
1-4244-0221-2
Type :
conf
DOI :
10.1109/INFOCOM.2006.27
Filename :
4146680
Link To Document :
بازگشت