Title :
Policy Distribution Methods for Function Parallel Firewalls
Author :
Horvath, Michael R. ; Fulp, Errin W. ; Wheeler, Patrick S.
Author_Institution :
GreatWall Syst., Winston-Salem, NC
Abstract :
Parallel firewalls offer a scalable low latency design for inspecting packets at high speeds. Typically consisting of an array of m firewalls, these systems filter arriving packets according to a security policy. Given the firewall array, the rules can be distributed in two fashions. Data parallel copies the entire policy to each firewall and distributes packets. In contrast, function parallel distributes the rules and duplicates packets. The function parallel design can provide significantly lower delays than an equivalent data parallel design, however performance is dependent on how the rules are distributed. Therefore, policy management is vital to the performance of the function parallel firewall system. This paper describes the guidelines necessary to maintain policy integrity, which guarantees that a function parallel and a traditional firewall provide the same action for a packet. Based on these requirements, a policy can be divided into autonomous chains (sub-policies) that can be distributed across the firewall array. Although determining the optimal distribution was shown to be NP-hard, an effective algorithm was described. Simulation results indicate the distribution algorithm can provide an 86% reduction in the average processing delay as compared to previous distribution methods.
Keywords :
authorisation; computational complexity; NP-hard; function parallel firewalls; policy distribution methods; security policy; Computer network management; Computer science; Data security; Delay; Filters; Guidelines; Inspection; Quality of service; Telecommunication traffic; Traffic control;
Conference_Titel :
Computer Communications and Networks, 2008. ICCCN '08. Proceedings of 17th International Conference on
Conference_Location :
St. Thomas, US Virgin Islands
Print_ISBN :
978-1-4244-2389-7
Electronic_ISBN :
1095-2055
DOI :
10.1109/ICCCN.2008.ECP.121