• DocumentCode
    2912221
  • Title

    Disarming firewall

  • Author

    Shaikh, Zubair A. ; Ahmed, Furqan

  • Author_Institution
    Dept. of Comput. Sci., FAST NUCES, Karachi, Pakistan
  • fYear
    2010
  • fDate
    14-16 June 2010
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    We have focused on a particular mechanism of providing network security: firewall technology. Firewalls provide a false sense of security because they have inherent flaws that are continuously exploited by hackers. Current firewalls lack in providing adequate security against insiders. Literature suggests that these limitations arise from the deficiencies in firewall design. This paper presents a model of a firewall called disarming firewall. The model is composed of different components, each serving different purpose. The firewall protects against malicious insiders by limiting the attacking capabilities of each internal host. Knowing that obtaining knowledge of end systems is a precursor of an attack, the firewall hides the identity of OS and server software placed in DMZ from internal as well as external users. Another problem solved by the firewall is the general laziness in applying patches to the software. The auditing system of firewall actively monitors all systems in the perimeter and applies patches as soon as they are released.
  • Keywords
    authorisation; computer crime; operating systems (computers); auditing system; disarming firewall; hackers; network security; operating system; server software; Authentication; Fires; Internet; Monitoring; Servers; Software; Disarmed Host; Firewall; Network Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information and Emerging Technologies (ICIET), 2010 International Conference on
  • Conference_Location
    Karachi
  • Print_ISBN
    978-1-4244-8001-2
  • Type

    conf

  • DOI
    10.1109/ICIET.2010.5625739
  • Filename
    5625739