FT-FW:: Efficient connection failover in cluster-based stateful firewall

被引:3
|
作者
Neira, P. [1 ]
Gasca, R. M. [1 ]
Lefevre, L. [2 ,3 ]
机构
[1] QUIVIR Res Grp, Dept Language & Sysy, ETS Ingn Informat, Avda Reina Mercedes,S-N, Seville 41012, Spain
[2] Univ Lyon, INRIA RESO, LIP Lab, F-69622 Villeurbanne, France
[3] Ecole Normale Super Lyon, CNRS, INRIA ENS UCB, UMR, F-69364 Lyon, France
关键词
D O I
10.1109/PDP.2008.87
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Stateful firewalls are security solutions widely deployed in the Inter-net. These devices filter network traffic and keep track of the state of connections in order to make the deployment of several attacks, such as TCP resets, difficult. However, firewalls are critical equipments in the network schema since they introduce a single point of failure. Therefore, a failure may isolate networks, users and interrupt established connections. Current fault tolerant solutions mask failures by means of replication techniques based on physical redundancy and state propagation. However, these solutions do not suit well for stateful firewall scenarios since they reduce bandwidth throughput roughly, they require costful extra hardware or are stuck to wasteful and inflexible single primary-backup settings. In this work we detail FT-FW (Fault Tolerant FireWall), a software-based transparent connection failover mechanism for stateful firewalls. Our solution has a negligible impact in terms of performance, as well as the fact that quick recovery from failures and fast responses to clients are guaranteed. The architecture is suitable for low cost off-the-shelf systems and no extra hardware is required.
引用
收藏
页码:573 / +
页数:2
相关论文
共 50 条
  • [31] An Energy-Efficient Cluster-Based Routing in Wireless Sensor Networks
    Cho, Seongsoo
    Shrestha, Bhanu
    La, Keuk-Hwan
    Hong, Bonghwa
    Lee, Jongsup
    COMMUNICATION AND NETWORKING, PT I, 2011, 265 : 15 - +
  • [32] Energy Efficient Cluster-Based Optimal Resource Management in IoT Environment
    Anchitaalagammai, J., V
    Jayasankar, T.
    Selvaraj, P.
    Sikkandar, Mohamed Yacin
    Zakarya, M.
    Elhoseny, Mohamed
    Shankar, K.
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 70 (01): : 1247 - 1261
  • [33] Energy-efficient cluster-based cooperative FEC in wireless networks
    Yi, Su
    Kalyanaraman, Shivkumar
    Azimi-Sadjadi, Babak
    Shen, Hsin-Yi
    WIRELESS NETWORKS, 2009, 15 (08) : 965 - 977
  • [34] An Efficient Energy Cluster-based Routing Protocol for Wireless Sensor Networks
    Bao Xi-rong
    Qie Zhi-tao
    Zhang Xue-feng
    Zhang Shi
    CCDC 2009: 21ST CHINESE CONTROL AND DECISION CONFERENCE, VOLS 1-6, PROCEEDINGS, 2009, : 4716 - +
  • [35] An Energy Efficient and Reliable Cluster-based Adaptive MAC protocol for UWSN
    Zenia, Nusrat Z.
    Kaiser, M. S.
    Ahmed, M. R.
    Mamun, S. A.
    Islam, M. S.
    2ND INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING AND INFORMATION COMMUNICATION TECHNOLOGY (ICEEICT 2015), 2015,
  • [36] An efficient intrusion detection framework in cluster-based wireless sensor networks
    Sedjelmaci, Hichem
    Senouci, Sidi Mohammed
    Feham, Mohammed
    SECURITY AND COMMUNICATION NETWORKS, 2013, 6 (10) : 1211 - 1224
  • [37] Efficient Cluster-Based k-Nearest-Neighbor Machine Translation
    Wang, Dexin
    Fan, Kai
    Chen, Boxing
    Xiong, Deyi
    PROCEEDINGS OF THE 60TH ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2022), VOL 1: (LONG PAPERS), 2022, : 2175 - 2187
  • [38] Efficient support for P-HTTP in cluster-based Web servers
    Aron, M
    Druschel, P
    Zwaenepoel, W
    PROCEEDINGS OF THE 1999 USENIX ANNUAL TECHNICAL CONFERENCE, 1999, : 185 - 198
  • [39] Energy-efficient cluster-based cooperative FEC in wireless networks
    Su Yi
    Shivkumar Kalyanaraman
    Babak Azimi-Sadjadi
    Hsin-Yi Shen
    Wireless Networks, 2009, 15 : 965 - 977
  • [40] Energy Efficient Hierarchical Cluster-Based Routing for Wireless Sensor Networks
    Shirazi, Shideh Sadat
    Haqiqat, Aboulfazl Torqi
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2016, 16 (04): : 115 - 119