A Proposal for Dynamic Access Lists for TCP/IP Packet Filering
نویسنده
چکیده
The use of IP filtering as a means of improving system security is well established. Although there are limitations at what can be achieved doing relatively low-level filtering, IP level filtering has proved to be efficient and effective. In the design of a security policy there is always a trade-off between usability and security. Restricting access means that legitimate use of the network is prevented; allowing access means illegitimate use may be allowed. Static access list make finding a balance particularly stark — we pay the price of decreased security 100% of the time even if the benefit of increased usability is only gained 1% of the time. Dynamic access lists would allow the rules to change for short periods of time, and to allow local changes by non-experts. The network administrator can set basic security guide-lines which allow certain basic services only. All other services are restricted, but users are able to request temporary exceptions in order to allow additional access to the network. These exceptions are granted depending on the privileges of the user. This paper covers the following topics: (1) basic introduction to TCP/IP filtering; (2) semantics for dynamic access lists and; (3) a proposed protocol for allowing dynamic access; and (4) a method for representing access lists so that dynamic update and look-up can be done efficiently.
منابع مشابه
Semantics, implementation and performance of dynamic access lists for TCP/IP packet filtering
The use of IP filtering to improve system security is well established, and although limited in what it can achieve has proved to be efficient and effective. In the design of a security policy there is always a trade-off between usability and security. Static access lists make finding a balance particularly stark. Dynamic access lists would allow the rules to change for short periods of time, a...
متن کاملDynamic Mobile IP and Nice-TCP for Improving TCP/IP Performance
1 This research was based on work supported by the National Science Foundation under Grant No. IIS 19979453. Abstract Mobile IP is an Internet protocol designed to support host mobility. It provides the host the ability to stay connected to the Internet regardless of its location. This paper presents a modified Mobile IP protocol, (Dynamic Mobile (IP-DM-IP)). DM-IP eliminates triangular routing...
متن کامل“ TCP Over OBS : To Split or Not To Split ? ”
Internet technology has advanced significantly over last decade. Now Internet is used not only to check emails or access information. Today’s Internet demands services such as video on demand, grid computing and very high data send rates which are bursty in nature. Current technology is unable to service such high bandwidth demands. Optical Burst Switching (OBS) technology shows huge potential ...
متن کاملNetwork Access Capacity Estimation through Passive Traffic Measurement
This work proposes models, techniques and tools aimed at passively estimating the maximum achievable downlink network-layer bandwidth (capacity) of an access link to the Internet from inside a network. The Internet access capacity estimation by mean of passive measurements is an interesting issue from a scientific and from an industrial perspective. From a scientific perspective the problem, st...
متن کاملTCP Implementation in Linux: A Brief Tutorial
Figures 1 and 2 show the internals of the TCP implementation in Linux kernel. Fig. 1 shows the path taken by a new packet from the the wire to a user application. The Linux kernel uses an sk buff data structure to describe each packet. When a packet arrives at the NIC, it invokes the DMA engine to place the packet into the kernel memory via empty sk buffs stored in a ring buffer called rx ring....
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- CoRR
دوره cs.NI/0110013 شماره
صفحات -
تاریخ انتشار 2001