• DocumentCode
    3255102
  • Title

    Stochastic Pre-Classification for Software Defined Firewalls

  • Author

    Ghoshal, Probir ; Casey, C. Jasson ; Gratz, Paul V. ; Sprintson, Alex

  • Author_Institution
    Qualcomm Technol., Inc. (QTI), Raleigh, NC, USA
  • fYear
    2013
  • fDate
    July 30 2013-Aug. 2 2013
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    Firewalls are ubiquitous security functions and exist in almost all network connected devices whether protecting host stacks or providing transient packet filtering. Firewall performance, which is a key ingredient for network performance, can be greatly degraded by traffic crafted to exploit its filtering algorithms. These attacks can greatly reduce the Quality of Service (QoS) received by existing authorized flows in the firewall. This paper proposes a novel architecture that decouples this linkage between authorized flow QoS and adversarial traffic, marginalizing disruption caused by unauthorized flows, and ultimately improving overall performance of software defined firewalls. We show substantial improvements in throughput, packet loss, and latency over baseline software defined firewalls with varying ratios of attack traffic. All results are obtained using the cycle accurate architecture simulator gem5, and Internet packet traces obtained from 10 Gbps interfaces of core Internet routers.
  • Keywords
    Internet; firewalls; quality of service; software radio; telecommunication network routing; telecommunication security; telecommunication traffic; Internet packet traces; Internet routers; adversarial traffic; architecture simulator; authorized flow QoS; baseline software defined firewalls; filtering algorithms; firewall performance; gem5; host stacks; marginalizing disruption; network connected devices; packet loss; quality of service; software defined firewalls; stochastic preclassification; transient packet filtering; ubiquitous security functions; Bandwidth; Data structures; Entropy; Hardware; Quality of service; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks (ICCCN), 2013 22nd International Conference on
  • Conference_Location
    Nassau
  • Print_ISBN
    978-1-4673-5774-6
  • Type

    conf

  • DOI
    10.1109/ICCCN.2013.6614198
  • Filename
    6614198