DocumentCode
2912221
Title
Disarming firewall
Author
Shaikh, Zubair A. ; Ahmed, Furqan
Author_Institution
Dept. of Comput. Sci., FAST NUCES, Karachi, Pakistan
fYear
2010
fDate
14-16 June 2010
Firstpage
1
Lastpage
6
Abstract
We have focused on a particular mechanism of providing network security: firewall technology. Firewalls provide a false sense of security because they have inherent flaws that are continuously exploited by hackers. Current firewalls lack in providing adequate security against insiders. Literature suggests that these limitations arise from the deficiencies in firewall design. This paper presents a model of a firewall called disarming firewall. The model is composed of different components, each serving different purpose. The firewall protects against malicious insiders by limiting the attacking capabilities of each internal host. Knowing that obtaining knowledge of end systems is a precursor of an attack, the firewall hides the identity of OS and server software placed in DMZ from internal as well as external users. Another problem solved by the firewall is the general laziness in applying patches to the software. The auditing system of firewall actively monitors all systems in the perimeter and applies patches as soon as they are released.
Keywords
authorisation; computer crime; operating systems (computers); auditing system; disarming firewall; hackers; network security; operating system; server software; Authentication; Fires; Internet; Monitoring; Servers; Software; Disarmed Host; Firewall; Network Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Information and Emerging Technologies (ICIET), 2010 International Conference on
Conference_Location
Karachi
Print_ISBN
978-1-4244-8001-2
Type
conf
DOI
10.1109/ICIET.2010.5625739
Filename
5625739
Link To Document