• DocumentCode
    3050265
  • Title

    An Enhanced Firewall Scheme for Dynamic and Adaptive Containment of Emerging Security Threats

  • Author

    Castiglione, Aniello ; De Santis, Alfredo ; Fiore, Ugo ; Palmieri, Francesco

  • Author_Institution
    Dip. di Inf. ed Applicazioni R.M. Capocelli, Univ. di Salerno, Fisciano, Italy
  • fYear
    2010
  • fDate
    4-6 Nov. 2010
  • Firstpage
    475
  • Lastpage
    481
  • Abstract
    Due to the increasing threat of attacks and malicious activities, the use of firewall technology is an important milestone toward making networks of any complexity and size secure. Unfortunately, the inherent difficulties in designing and managing firewall policies within the modern highly distributed, dynamic and heterogeneous environments might greatly limit the effectiveness of firewall security. It is therefore desirable to automate as much as possible the firewall configuration process. Accordingly, this work presents a new more active and scalable fire walling architecture based on dynamic and adaptive policy management facilities, thus enabling the automatic generation of new rules and policies, to ensure a timely response in detecting unusual traffic activity and identify unknown potential attacks (0day). The proposed scheme, structured in a multi-stage modular fashion, can be easily applied in a distributed security environment, and does not depend on specific security solutions or hardware/software packages.
  • Keywords
    computer network management; computer network security; enhanced firewall scheme; firewall policies management; firewall security; security threats; Fires; IP networks; Object oriented modeling; Optimization; Performance evaluation; Protocols; Security; Adaptive Policy Management; Firewall Management and Design; Multi-Firewall Systems; Network Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Broadband, Wireless Computing, Communication and Applications (BWCCA), 2010 International Conference on
  • Conference_Location
    Fukuoka
  • Print_ISBN
    978-1-4244-8448-5
  • Electronic_ISBN
    978-0-7695-4236-2
  • Type

    conf

  • DOI
    10.1109/BWCCA.2010.117
  • Filename
    5633666