{"title":"FIEP:防火墙信息交换协议的初始设计","authors":"Sandeep Reddy Pedditi, Du Zhang, Chung-E Wang","doi":"10.1109/IRI.2013.6642446","DOIUrl":null,"url":null,"abstract":"FIEP, which stands for Firewall Information Exchange Protocol, is a mechanism that enables firewalls to communicate with each other and to form firewall groups in a network. Currently, there is no protocol that allows firewalls to communicate with each other and to exchange information. Until recently, not much thought was given to the need for firewalls to talk to each other. A firewalled network is isolated from the rest of the networks and is considered to be secure. But a firewalled network is not totally secure as it is still prone to distributed attacks. The objective of developing FIEP is to further strengthen the network security through firewalls sharing information with each other and keeping each other informed of any status changes. Like the Border Gateway Protocol (BGP) that enables routers to exchange routing information and keeps them updated, FIEP allows the firewalls to update each other on changes of access control rules, to form groups and notify members in a group of new and removed firewalls, and to alert each other in the network about attacks. FIEP is a TCP/IP based protocol that provides a communication mechanism for two or more firewalls to communicate with each other, and sanctions both static and dynamic configurations of firewalls. The initial design of FIEP includes three modes of communication among firewalls and has a set of seven states. The initial simulation results are promising.","PeriodicalId":418492,"journal":{"name":"2013 IEEE 14th International Conference on Information Reuse & Integration (IRI)","volume":"127 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-10-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"FIEP: An initial design of a firewall information exchange protocol\",\"authors\":\"Sandeep Reddy Pedditi, Du Zhang, Chung-E Wang\",\"doi\":\"10.1109/IRI.2013.6642446\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"FIEP, which stands for Firewall Information Exchange Protocol, is a mechanism that enables firewalls to communicate with each other and to form firewall groups in a network. Currently, there is no protocol that allows firewalls to communicate with each other and to exchange information. Until recently, not much thought was given to the need for firewalls to talk to each other. A firewalled network is isolated from the rest of the networks and is considered to be secure. But a firewalled network is not totally secure as it is still prone to distributed attacks. The objective of developing FIEP is to further strengthen the network security through firewalls sharing information with each other and keeping each other informed of any status changes. Like the Border Gateway Protocol (BGP) that enables routers to exchange routing information and keeps them updated, FIEP allows the firewalls to update each other on changes of access control rules, to form groups and notify members in a group of new and removed firewalls, and to alert each other in the network about attacks. FIEP is a TCP/IP based protocol that provides a communication mechanism for two or more firewalls to communicate with each other, and sanctions both static and dynamic configurations of firewalls. The initial design of FIEP includes three modes of communication among firewalls and has a set of seven states. The initial simulation results are promising.\",\"PeriodicalId\":418492,\"journal\":{\"name\":\"2013 IEEE 14th International Conference on Information Reuse & Integration (IRI)\",\"volume\":\"127 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-10-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2013 IEEE 14th International Conference on Information Reuse & Integration (IRI)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IRI.2013.6642446\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 IEEE 14th International Conference on Information Reuse & Integration (IRI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IRI.2013.6642446","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
摘要
FIEP是防火墙信息交换协议(Firewall Information Exchange Protocol)的缩写,它是一种使防火墙能够相互通信并在网络中形成防火墙组的机制。目前,还没有协议允许防火墙相互通信和交换信息。直到最近,人们还没有过多地考虑防火墙相互通信的必要性。防火墙网络与其他网络隔离,被认为是安全的。但是有防火墙的网络并不是完全安全的,因为它仍然容易受到分布式攻击。发展FIEP的目的是通过防火墙进一步加强网络安全,彼此共享信息,并随时通知任何状态变化。与边界网关协议BGP (Border Gateway Protocol, BGP)一样,FIEP允许防火墙在访问控制规则的变化时相互更新,在一组新的和被删除的防火墙中组成组并通知成员,并在网络中相互警告攻击。FIEP是一种基于TCP/IP的协议,它为两个或多个防火墙提供了相互通信的通信机制,并支持防火墙的静态和动态配置。FIEP的初始设计包括防火墙之间的三种通信模式,并具有七种状态。初步的仿真结果令人满意。
FIEP: An initial design of a firewall information exchange protocol
FIEP, which stands for Firewall Information Exchange Protocol, is a mechanism that enables firewalls to communicate with each other and to form firewall groups in a network. Currently, there is no protocol that allows firewalls to communicate with each other and to exchange information. Until recently, not much thought was given to the need for firewalls to talk to each other. A firewalled network is isolated from the rest of the networks and is considered to be secure. But a firewalled network is not totally secure as it is still prone to distributed attacks. The objective of developing FIEP is to further strengthen the network security through firewalls sharing information with each other and keeping each other informed of any status changes. Like the Border Gateway Protocol (BGP) that enables routers to exchange routing information and keeps them updated, FIEP allows the firewalls to update each other on changes of access control rules, to form groups and notify members in a group of new and removed firewalls, and to alert each other in the network about attacks. FIEP is a TCP/IP based protocol that provides a communication mechanism for two or more firewalls to communicate with each other, and sanctions both static and dynamic configurations of firewalls. The initial design of FIEP includes three modes of communication among firewalls and has a set of seven states. The initial simulation results are promising.