Document
Optimization of parallel firewalls filtering rules
Linked Agent
Title of Periodical
International Journal of Information Security
Country of Publication
Kingdom of Bahrain
Place Published
Sakhir . Bahrain
Publisher
University of Bahrain
Date Issued
2022
Language
English
Subject
English Abstract
Abstract:
As filtering policies are getting larger and more complex, packet filtering at firewalls needs to keep low delays. New firewall architectures are needed to enforce security and meet the increasing demand for high-speed networks. Two main architectures exist for parallelization, data-parallel and function-parallel firewalls. In the first, packets are distributed across a set of identical firewalls that implement the entire policy. In the second, each firewall implements a subset of the policy with a fewer number of rules, but the packets have to be duplicated and processed by all the firewalls. This paper proposes a new architecture function-parallel with pre-processing that combines the advantages of both architectures. The proposed architecture has the
advantage of not duplicating the data, so that the processing time can be significantly reduced. Moreover, our architecture enables stateful inspection of packets, which is necessary to prevent multiple types of attacks. The performances of this architecture have been proven to be scalable for large security policies.
Member of
Identifier
https://digitalrepository.uob.edu.bh/id/c3e15550-3d50-4f20-8bc4-77d1e82a636f
Same Subject