功能并行防火墙的策略分发方法

Michael R. Horvath, E. Fulp, Patrick S. Wheeler
{"title":"功能并行防火墙的策略分发方法","authors":"Michael R. Horvath, E. Fulp, Patrick S. Wheeler","doi":"10.1109/ICCCN.2008.ECP.121","DOIUrl":null,"url":null,"abstract":"Parallel firewalls offer a scalable low latency design for inspecting packets at high speeds. Typically consisting of an array of m firewalls, these systems filter arriving packets according to a security policy. Given the firewall array, the rules can be distributed in two fashions. Data parallel copies the entire policy to each firewall and distributes packets. In contrast, function parallel distributes the rules and duplicates packets. The function parallel design can provide significantly lower delays than an equivalent data parallel design, however performance is dependent on how the rules are distributed. Therefore, policy management is vital to the performance of the function parallel firewall system. This paper describes the guidelines necessary to maintain policy integrity, which guarantees that a function parallel and a traditional firewall provide the same action for a packet. Based on these requirements, a policy can be divided into autonomous chains (sub-policies) that can be distributed across the firewall array. Although determining the optimal distribution was shown to be NP-hard, an effective algorithm was described. Simulation results indicate the distribution algorithm can provide an 86% reduction in the average processing delay as compared to previous distribution methods.","PeriodicalId":314071,"journal":{"name":"2008 Proceedings of 17th International Conference on Computer Communications and Networks","volume":"49 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2008-11-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"Policy Distribution Methods for Function Parallel Firewalls\",\"authors\":\"Michael R. Horvath, E. Fulp, Patrick S. Wheeler\",\"doi\":\"10.1109/ICCCN.2008.ECP.121\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Parallel firewalls offer a scalable low latency design for inspecting packets at high speeds. Typically consisting of an array of m firewalls, these systems filter arriving packets according to a security policy. Given the firewall array, the rules can be distributed in two fashions. Data parallel copies the entire policy to each firewall and distributes packets. In contrast, function parallel distributes the rules and duplicates packets. The function parallel design can provide significantly lower delays than an equivalent data parallel design, however performance is dependent on how the rules are distributed. Therefore, policy management is vital to the performance of the function parallel firewall system. This paper describes the guidelines necessary to maintain policy integrity, which guarantees that a function parallel and a traditional firewall provide the same action for a packet. Based on these requirements, a policy can be divided into autonomous chains (sub-policies) that can be distributed across the firewall array. Although determining the optimal distribution was shown to be NP-hard, an effective algorithm was described. Simulation results indicate the distribution algorithm can provide an 86% reduction in the average processing delay as compared to previous distribution methods.\",\"PeriodicalId\":314071,\"journal\":{\"name\":\"2008 Proceedings of 17th International Conference on Computer Communications and Networks\",\"volume\":\"49 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2008-11-17\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2008 Proceedings of 17th International Conference on Computer Communications and Networks\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICCCN.2008.ECP.121\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2008 Proceedings of 17th International Conference on Computer Communications and Networks","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCCN.2008.ECP.121","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

摘要

并行防火墙为高速检查数据包提供了可伸缩的低延迟设计。这些系统通常由一组防火墙组成,根据安全策略过滤到达的数据包。给定防火墙数组,规则可以以两种方式分发。数据并行将整个策略复制到每个防火墙,并分发报文。而功能并行则是分配规则和重复报文。函数并行设计可以提供比等效数据并行设计低得多的延迟,但是性能取决于规则的分布方式。因此,策略管理对功能并行防火墙系统的性能至关重要。本文描述了维护策略完整性所需的指导方针,这保证了并行功能和传统防火墙为数据包提供相同的操作。根据这些需求,可以将策略划分为自治链(子策略),这些自治链可以分布在整个防火墙阵列中。虽然确定最优分布被证明是np困难的,但描述了一种有效的算法。仿真结果表明,与以前的分布方法相比,该分布算法可将平均处理延迟降低86%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Policy Distribution Methods for Function Parallel Firewalls
Parallel firewalls offer a scalable low latency design for inspecting packets at high speeds. Typically consisting of an array of m firewalls, these systems filter arriving packets according to a security policy. Given the firewall array, the rules can be distributed in two fashions. Data parallel copies the entire policy to each firewall and distributes packets. In contrast, function parallel distributes the rules and duplicates packets. The function parallel design can provide significantly lower delays than an equivalent data parallel design, however performance is dependent on how the rules are distributed. Therefore, policy management is vital to the performance of the function parallel firewall system. This paper describes the guidelines necessary to maintain policy integrity, which guarantees that a function parallel and a traditional firewall provide the same action for a packet. Based on these requirements, a policy can be divided into autonomous chains (sub-policies) that can be distributed across the firewall array. Although determining the optimal distribution was shown to be NP-hard, an effective algorithm was described. Simulation results indicate the distribution algorithm can provide an 86% reduction in the average processing delay as compared to previous distribution methods.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信