Performance analysis of the Linux firewall in a host
نویسنده
چکیده
Firewalls are one of the most commonly used security systems to protect networks and hosts. Most researchers have focused on analyzing the latency and throughput of router firewalls. Different from this approach, this research focuses on studying the performance impact and the sensitivity of the Linux firewall (iptables) for a single host. In order to be able to measure the performance and the sensitivity of the firewall, we designed and instrumented each layer of the Linux TCP/IP stack. This instrumentation was used to test the host’s firewall under two scenarios: In the first scenario, we captured the path and the latency of one single packet; in the second scenario, we captured the latency of multiple packets sent to the host at various transmission rates. Our measurement results indicate that the firewall is sensitive to the number of rules, the type of filtering, and the transmission rate. The results of our first scenario demonstrate that for each type of filtering, latency increases linearly as the number of rules increase. Furthermore, the second test scenario shows that latency decreases as the packet transmission rate increases. The results also show that the percentage overhead generated by a firewall when a single packet of 64 bytes of payload travels the TCP/IP stack, for a rule-set of zero and 100 rules, ranges from 6% to up to 75%, respectively.
منابع مشابه
A Simple, Configurable, and Adaptive Network Firewall for Linux
It is increasingly important that workstations, especially those with permanent connections to the Internet, be defended against network delivered attacks. Firewalls constititute a useful component of the defense arsenal. However, the standard Linux tools for constructing firewalls have significant limitations. Simple firewalls can be built, but they protect at one of two extremes. They either ...
متن کاملVisual Firewall Rule Builder
The paper that is being submitted deals primarily with the implementation of firewall technology on Linux based systems. It focuses on the features of the visual medium for the creation and management of firewall rules, Visual Firewall Rule Builder – VFRB. VFRB has been written in Java and has a modular construction. The program consists of an object-oriented graphical user interface and a poli...
متن کاملUsing NetFPGA to Offload Linux Netfilter Firewall
The bandwidth of network traffic has also increased significantly along with the growth of the Internet bandwidth. Network-intensive application systems, such as web server and realtime streaming server, etc, must be capable of filtering malicious packets in a high traffic environment. However, firewall functions and network applications share common CPU resources for server equipping software-...
متن کاملOPTWALL: A Hierarchical Traffic-Aware Firewall
The overall efficiency, reliability, and availability of a firewall is crucial in enforcing and administrating security, especially when the network is under attack. The continuous growth of the Internet, coupled with the increasing sophistication of the attacks, is placing stringent demands on firewall performance. These challenges require new designs, architecture and algorithms to optimize f...
متن کاملA Set-based Approach to Packet Classification
Firewalls, and packet classification in general, are becoming more and more significant as data rates soar and hackers become increasingly sophisticated and more forceful. In this paper, we present a new packetclassification approach that uses set theory to classify packets. This approach has significant theoretical advantages over current approaches. We demonstrate its practicality by implemen...
متن کامل