Firewalls in an OSI-environment
نویسندگان
چکیده
A firewall is a well established security measure for connecting to the Internet (TCP/IP protocol suite). Government procurement profiles for data communication products (GOSIPs Government OSI Profile) usually demand use of official international standards, as defined by the International Standards Organization (ISO). ISO has defined a framework for Open Systems Interconnection (OSI), and develops protocol specifications (ISO-protocols) to fit in this framework. It can be assumed that firewalls are going to be an important security measure also when using ISO-protocols. But firewall products for ISO-protocols remain still to be seen, and little research has been done regarding firewalls in an OSI-environment. This paper discusses the consequences of introducing ISO-protocols from a firewalls point of view. As one might suspect, it is not trivial to transform from TCP/IP to OSI in this matter. Fundamental problems are presented, and recommendations are given on how to solve them. Use of a firewall to map between internal and external security policies is discussed.
منابع مشابه
Framework for Data-intensive Applications Optimizationin Large-scale Distributed Systems
ed network topology The real network topology is abstracted as a graph within the optimizer, based on the available network segments reported by all the distributed monitoring services. This graph includes a set of nodes, interconnected through a 94 Cătălin Cîrstoiu, Nicolae Ţăpuş number of links with additional information. The algorithms implemented in the optimizer will run over this abstrac...
متن کاملA programming environment for distributed applications based on OSI application services
However, the practical use of the OSI protocols for distributed applications is complicated today by the numerous design choices left to an application developer by the OSI upper-layer standards. Development tools for OSI upper layers existing today do not address this issue. Thus, the developer of a distributed application has to be an expert on the OSI upper layer standard documents to be abl...
متن کاملProposal for a Practical Cipher Communication Protocol That Can Coexist with NAT and Firewalls
Threats to network security have become a serious problem, and encryption technologies for communications are an important issue these days. Although the security of IPsec ESP (, that is a typical existing cipher communication technology) is strong, it has such problems that it can not be used in the environment where it coexists with NAT and firewalls, and that there also exists some degradati...
متن کاملIntranet Security via Firewalls
Firewalls, forefront defense for corporate intranet security, filter traffic by comparing arriving packets against stored security policies in a sequential manner. In a large organization, traffic typically goes through several firewalls before it reaches the destination. Setting polices device-by-device in an organization with large number of firewalls may easily create conflicts in policies. ...
متن کاملThe Use of Allomorphism for the Access Control Service in OSI Management Environment
This paper proposes the use of Allomorphism for the access control service in OSI management environment, with no Access Control Function implementation (IS010164-9, 1990), which is responsible for this service. The Allomorphism is a powerful SMI resource that makes the OSI Model very strong and flexible. This strategy reduces the overhead introduced by the access control function on OSI manage...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- Computer Communications
دوره 19 شماره
صفحات -
تاریخ انتشار 1996