Principles of Eliminating Access Control Lists within a Domain
نویسندگان
چکیده
The infrastructure of large networks is broken down into areas that have a common security policy called a domain. Security within a domain is commonly implemented at all nodes. However this can have a negative effect on performance since it introduces a delay associated with packet filtering. When Access Control Lists (ACLs) are used within a router for this purpose then a significant overhead is introduced associated with this process. It is likely that identical checks are made at multiple points within a domain prior to a packet reaching its destination. Therefore by eliminating ACLs within a domain by modifying the ingress/egress points with equivalent functionality an improvement in the overall performance can be obtained. This paper considers the effect of the delays when using router operating systems offering different levels of functionality. It considers factors which contribute to the delay particularly due to ACLs and by using theoretical principles modified by practical calculation a model is created. Additionally this paper provides an example of an optimized solution which reduces the delay through network routers by distributing the security rules to the ingress/egress points of the domain without affecting the security policy.
منابع مشابه
Authentication and Access Control in Sympa Mailing List Software
Sympa was designed to manage multiple mailing lists built on a common base, rather than being only side-byside mailing lists without any link between them. The system's architecture puts the virtual mailing list servers under the control of the various listmasters, each of which manages its own set of mailing lists. Like Apache’s virtual host, Sympa can manage numerous mailing list services (ca...
متن کاملA Fair Power Allocation for Non-Orthogonal Multiple Access in the Power Domain
This paper presents an investigation on the performance of the Non-Orthogonal Multiple Access (NOMA) in the power domain scheme. A Power Allocation (PA) method is proposed from NOMA throughput expression analysis. This method aims to provide fair opportunities for users to improve their performance. Thus, NOMA users can achieve rates higher than, or equal to, the rates obtained with the convent...
متن کاملA model for specification, composition and verification of access control policies and its application to web services
Despite significant advances in the access control domain, requirements of new computational environments like web services still raise new challenges. Lack of appropriate method for specification of access control policies (ACPs), composition, verification and analysis of them have all made the access control in the composition of web services a complicated problem. In this paper, a new indepe...
متن کاملProblems in Implementing Flexible Group Communication with Email
Group communication with email is performed by multicast making use of mailing lists. However, it is not quite possible to exclude any member out of the list temporarily. We try and apply some of the set operations to the destination address of a message to solve the problem. The idea is viewing email addresses as a language. Our prototype system works within a domain, however, in reality maili...
متن کاملQuantum Interference Control of Ballistic Magneto- resistance in a Magnetic Nanowire Containing Two Atomic- Size Domain Walls
The magnetoresistance of a one-dimensional electron gas in a metallic ferromagnetic nanowire containing two atomic-size domain walls has been investigated in the presence of spin-orbit interaction. The magnetoresistance is calculated in the ballistic regime, within the Landauer-Büttiker formalism. It has been demonstrated that the conductance of a magnetic nanowire with double domain walls...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید
ثبت ناماگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید
ورودعنوان ژورنال:
- Future Internet
دوره 4 شماره
صفحات -
تاریخ انتشار 2012