Title :
Stochastic Pre-Classification for Software Defined Firewalls
Author :
Ghoshal, Probir ; Casey, C. Jasson ; Gratz, Paul V. ; Sprintson, Alex
Author_Institution :
Qualcomm Technol., Inc. (QTI), Raleigh, NC, USA
fDate :
July 30 2013-Aug. 2 2013
Abstract :
Firewalls are ubiquitous security functions and exist in almost all network connected devices whether protecting host stacks or providing transient packet filtering. Firewall performance, which is a key ingredient for network performance, can be greatly degraded by traffic crafted to exploit its filtering algorithms. These attacks can greatly reduce the Quality of Service (QoS) received by existing authorized flows in the firewall. This paper proposes a novel architecture that decouples this linkage between authorized flow QoS and adversarial traffic, marginalizing disruption caused by unauthorized flows, and ultimately improving overall performance of software defined firewalls. We show substantial improvements in throughput, packet loss, and latency over baseline software defined firewalls with varying ratios of attack traffic. All results are obtained using the cycle accurate architecture simulator gem5, and Internet packet traces obtained from 10 Gbps interfaces of core Internet routers.
Keywords :
Internet; firewalls; quality of service; software radio; telecommunication network routing; telecommunication security; telecommunication traffic; Internet packet traces; Internet routers; adversarial traffic; architecture simulator; authorized flow QoS; baseline software defined firewalls; filtering algorithms; firewall performance; gem5; host stacks; marginalizing disruption; network connected devices; packet loss; quality of service; software defined firewalls; stochastic preclassification; transient packet filtering; ubiquitous security functions; Bandwidth; Data structures; Entropy; Hardware; Quality of service; Software;
Conference_Titel :
Computer Communications and Networks (ICCCN), 2013 22nd International Conference on
Conference_Location :
Nassau
Print_ISBN :
978-1-4673-5774-6
DOI :
10.1109/ICCCN.2013.6614198