Development framework for firewall processors
نویسندگان
چکیده
High-performance firewalls can benefit from the increasing size, speed and flexibility of advanced reconfigurable hardware. However, direct translation of conventional firewall rules in a router-based rule set often leads to inefficient hardware implementation. Moreover, such lowlevel description of firewall rules tends to be difficult to manage and to extend. We describe a framework, based on the high-level policy specification language Ponder, for capturing firewall rules as authorization policies with userdefinable constraints. Our framework supports optimisations to achieve efficient utilisation of hardware resources. A pipelined firewall implementation developed using this approach running at 10MHz is capable of processing 2.5 million packets per second, which provides similar performance to a version without optimisation and is about 50 times faster than a software implementation running on a 700MHz PIII processor.
منابع مشابه
Compiling Policy Descriptions into Reconfigurable Firewall Processors
We describe a framework for capturing firewall requirements as high-level descriptions based on the policy specification language Ponder. The framework provides abstraction from hardware implementation while allowing performance control through constraints. Our hardware compilation strategy for such descriptions involves a rule reduction step to produce a hardware firewall rule representation. ...
متن کاملAn Unavailability Analysis of Firewall Sandwich Configurations
Firewalls form the first line of defense in securing internal networks from the Internet. A Firewall only provides security if all traffic into and out of an internal network passes through the firewall. However, a single firewall through which all network traffic must flow represents a single point of failure. If the firewall is down, all access is lost. A common solution to this problem is to...
متن کاملMDA-Based Framework for Automatic Generation of Consistent Firewall ACLs with NAT
The design and management of firewall ACLs is a very hard and error-prone task. Part of this complexity comes from the fact that each firewall platform has its own low-level language with a different functionality, syntax, and development environment. Although several high-level languages have been proposed to model firewall access control policies, none of them has been widely adopted by the i...
متن کاملAn Assessment of the Effects of Root and Tuber Expansion Project (RTEP) on the Livelihood of Cassava Processors in Kwara State, Nigeria
The study was carried out to assess the effects of the Root and Tuber Expansion Programe (RTEP) on the livelihood of project beneficiaries in Kwara State, Nigeria. A 3-stage sampling technique was adopted for the study, selecting a total of 80 cassava processors from two Agricultural Development Programe (ADP) zones in the State. Structured interview schedule was used as instrument to elicit pr...
متن کاملAn Integrated Framework for Firewall Testing and Validation
An Integrated Framework for Automated Firewall Testing and Validation
متن کامل