FT-FW:: Efficient connection failover in cluster-based stateful firewall

被引:3
|
作者
Neira, P. [1 ]
Gasca, R. M. [1 ]
Lefevre, L. [2 ,3 ]
机构
[1] QUIVIR Res Grp, Dept Language & Sysy, ETS Ingn Informat, Avda Reina Mercedes,S-N, Seville 41012, Spain
[2] Univ Lyon, INRIA RESO, LIP Lab, F-69622 Villeurbanne, France
[3] Ecole Normale Super Lyon, CNRS, INRIA ENS UCB, UMR, F-69364 Lyon, France
关键词
D O I
10.1109/PDP.2008.87
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Stateful firewalls are security solutions widely deployed in the Inter-net. These devices filter network traffic and keep track of the state of connections in order to make the deployment of several attacks, such as TCP resets, difficult. However, firewalls are critical equipments in the network schema since they introduce a single point of failure. Therefore, a failure may isolate networks, users and interrupt established connections. Current fault tolerant solutions mask failures by means of replication techniques based on physical redundancy and state propagation. However, these solutions do not suit well for stateful firewall scenarios since they reduce bandwidth throughput roughly, they require costful extra hardware or are stuck to wasteful and inflexible single primary-backup settings. In this work we detail FT-FW (Fault Tolerant FireWall), a software-based transparent connection failover mechanism for stateful firewalls. Our solution has a negligible impact in terms of performance, as well as the fact that quick recovery from failures and fast responses to clients are guaranteed. The architecture is suitable for low cost off-the-shelf systems and no extra hardware is required.
引用
收藏
页码:573 / +
页数:2
相关论文
共 50 条
  • [1] FT-FW: A cluster-based fault-tolerant architecture for stateful firewalls
    Neira Ayuso, Pablo
    Gasca, Rafael M.
    Lefevre, Laurent
    COMPUTERS & SECURITY, 2012, 31 (04) : 524 - 539
  • [2] Multiprimary Support for the Availability of Cluster-Based Stateful Firewalls Using FT-FW
    Neira, P.
    Gasca, R. M.
    Lefevre, L.
    COMPUTER SECURITY - ESORIC 2008, PROCEEDINGS, 2008, 5283 : 1 - +
  • [3] hFT-FW: hybrid fault-tolerance for cluster-based Stateful Firewalls
    Neira, P.
    Gasca, R. M.
    Lefevre, L.
    PROCEEDINGS OF THE 2008 14TH IEEE INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, 2008, : 525 - +
  • [4] Efficient cluster-based portfolio optimization
    Bnouachir, Najla
    Mkhadri, Abdallah
    COMMUNICATIONS IN STATISTICS-SIMULATION AND COMPUTATION, 2021, 50 (11) : 3241 - 3255
  • [5] Efficient Cluster-Based Boosting for Semisupervised Classification
    Soares, Rodrigo G. F.
    Chen, Huanhuan
    Yao, Xin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2018, 29 (11) : 5667 - 5680
  • [6] Cluster-based Efficient Particle PHD Filter
    Wang, Junjie
    Zhao, Lingling
    Su, Xiaohong
    Sun, Rui
    Ma, Jiquan
    FOURTH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND INFORMATION SCIENCES (CCAIS 2015), 2015, : 219 - 224
  • [7] Efficient Coreset Selection with Cluster-based Methods
    Chai, Chengliang
    Wang, Jiayi
    Tang, Nan
    Yuan, Ye
    Liu, Jiabin
    Deng, Yuhao
    Wang, Guoren
    PROCEEDINGS OF THE 29TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2023, 2023, : 167 - 178
  • [8] ENERGY EFFICIENT CLUSTER-BASED TARGET TRACKING STRATEGY
    AL-Ghanem, Waleed
    Mahgoub, Imad
    Ilyas, Mohammad
    2009 6TH INTERNATIONAL SYMPOSIUM ON HIGH CAPACITY OPTICAL NETWORKS AND ENABLING TECHNOLOGIES (HONET 2009), 2009, : 198 - 204
  • [9] An efficient cluster-based hierarchical progressive radiosity algorithm
    Myszkowski, K
    Kunii, TL
    IMAGE ANALYSIS APPLICATIONS AND COMPUTER GRAPHICS, 1995, 1024 : 292 - 303
  • [10] Cluster-based efficient information dissemination in dynamic networks
    Yang, Zhiwei
    Wu, Weigang
    Li, Yong
    Chen, Yishun
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2018, 14 (03)