A Centralized State Repository Approach to Highly Scalable and High-Availability Parallel Firewall
نویسندگان
چکیده
Conventional high-availability stateful parallel firewall suffers from low scalability due to two overlapping requirements: workload distribution and redundancy. To achieve high throughput, load-distribution with complex algorithm is conventionally employed, consuming a lot of resources and making the system susceptible to state-related attacks such as SYN-flooding. On the other hand, making the system redundant usually implies N-to-N crossreplication of connection-state data among firewall nodes. These make the scaling effort very difficult at best. This paper presents the novel design and implementation of a highly scalable, high-availability, stateful parallel firewall with centralized state repository intending for high-speed connection environment. The system consists of fault sensor unit(s), fully redundant load manager units, fully redundant central state repository unit(s), and an array of Linux-based machines acting as firewall nodes under the data parallel scheme. Adding more units into the system can scale every component up. Consistent Disjoint-subset Hashing and Stateless Load balancing algorithms, chosen for their superior computing overhead, provide high performance, flexibility and scalability. Centralized State Repository further enhances reliability and scalability. Actual deployment statistics confirm that the combination of centralized state repository and on-demand state restoration largely reduces the number of state synchronization transactions when the number of firewall nodes fluctuates. Therefore, the high-scalability and load balancing are gained with minimal state replications.
منابع مشابه
Sparrow: Scalable Scheduling for Sub-Second Parallel Jobs
Large-scale data analytics frameworks are shifting towards shorter task durations and larger degrees of parallelism to provide low latency. However, scheduling highly parallel jobs that complete in hundreds of milliseconds poses a major challenge for cluster schedulers, which will need to place millions of tasks per second on appropriate nodes while offering millisecond-level latency and high a...
متن کاملInternet as Indispensable Everywhere: The Introduction to the Advances in Internet Technologies and Applications Special Issue
Research on internet technologies has attracted increasing interest in the past decade, as indicated by a growing number of conceptual and empirical articles. Studies [1,2] on internet usage show the following trend during the past two decades. Growth of internet users over the world from 2000 to 2012 has an increase of 566% and Asia has the growth of 842%. Currently, over 2.5 billion people in...
متن کاملComparing Parallel Simulated Annealing, Parallel Vibrating Damp Optimization and Genetic Algorithm for Joint Redundancy-Availability Problems in a Series-Parallel System with Multi-State Components
In this paper, we study different methods of solving joint redundancy-availability optimization for series-parallel systems with multi-state components. We analyzed various effective factors on system availability in order to determine the optimum number and version of components in each sub-system and consider the effects of improving failure rates of each component in each sub-system and impr...
متن کاملA Parallel Architecture for Stateful, High-Speed Intrusion Detection
The increase in bandwidth over processing power has made stateful intrusion detection for high-speed networks more difficult, and, in certain cases, impossible. The problem of real-time stateful intrusion detection in high-speed networks cannot easily be solved by optimizing the packet matching algorithm utilized by a centralized process or by using custom-developed hardware. Instead, there is ...
متن کاملManageable and Economical Connection of Centralized Repository Servers Using Server Ports
Objective of centralized repository is to arrange an outsized number of server machines with little apparatus cost while providing high planning facility and bisection width. It is well understand that the present practice where servers are linked by a tree hierarchy of network switches cannot gather these necessities. In this paper, we find out a newest serverinterconnection structure. The Str...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- JCP
دوره 8 شماره
صفحات -
تاریخ انتشار 2013