Traffic Management and Security Based on Priority Queueing and Multicore Firewall Implementation

نویسندگان

  • Vladimir S. Zaborovsky
  • Vladimir Mulukha
  • Sergey Kouprienko
  • Oleg Zayats
چکیده

We consider the telematics appliances, such as firewall, as a basic part of security system with specific preemptive priority queuing and access control algorithm oriented on multi-core implementation. Proposed randomized push-out buffer management mechanism with α parameter allows tuning very efficiently the loss probability of priority packets and the time they spend in queue as the factors used for firewall configuration. The packet losses probabilities for priority and non-priority traffic are calculated using the generating function approach and apply to network security policy. We suggest appointing parameter α to each virtual connection according to a security service policy. The service of each connection in firewall is done in correspondence with this parameter and if α=0 then packets pass our device without changes and delays with standard best effort mechanism, if 0<α<1 some packets are delayed/dropped and if α=1 all packets of virtual connection are prohibited.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Denial of Firewalling

Firewalls are critical security devices handling all traffic in and out of a network. When under heavy load of both malicious and legitimate traffic, firewalls may be overloaded and start discarding or permitting packets without checking firewall rules, which can cause huge revenue losses or security breaches. In this paper, we study Denial of Firewalling attacks, where attackers use well-craft...

متن کامل

Firewall Management for to Resolve the Policy Anomalies

Firewall is a security system for network, that controls the network traffic based on firewall rules. Firewall depends on the policy configuration, but managing that firewall policy is complex. Existing policy analysis tools, such as Firewall Policy Advisor and FIREMAN, they can only detect the policy anomaly cannot resolve these anomalies, and detection time was also increased. Therefore, I re...

متن کامل

An FPGA-based coprocessor for ATM firewalls

An agile firewall coprocessor is described that is based on field programmable gate array (FPGA) technology. This implementation of the firewall enables a high degree of traffic selectability yet avoids the usual performance penalty associated with IP level firewalls. This approach is applicable to high-speed broadband networks, and Asynchronous Transfer Mode (ATM) networks are addressed in par...

متن کامل

Test Case Generation for Firewall Testing

Tugkan Tuglular Dept. of Computer Engineering, Izmir Institute of Technology, Izmir, Turkey [email protected] Firewall tests have to be performed to verify that the firewall works as specified. In this work, a test case generation approach is developed, which defines test cases based on the firewall rule sequence and uses real traffic database to prepare test packets. Test packets can ...

متن کامل

Performance of a Linux Implementation of Class Based Queueing

Class Based Queueing (CBQ) is a link-sharing and resource management mechanism for packet networks. We have ported the CBQ implementation on FreeBSD, also known as Alternate Queueing (ALTQ), to the Linux platform. This paper investigates the performance of CBQ in terms of latency, bandwidth guarantee and delay. CBQ is found to be able to preserve bandwidth allocated to the classes. However, it ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010