Dynamic balancing of packet filtering workloads on distributed firewalls

被引:0
|
作者
Yan, Guanhua [1 ]
Chen, Songqing [2 ]
Eidenbenz, Stephan [1 ]
机构
[1] Los Alamos Natl Lab, Informat Sci CCS 3, Los Alamos, NM 87545 USA
[2] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls are widely deployed nowadays to enforce security policies of enterprise networks. While having played crucial roles in securing these networks, firewalls themselves are subject to performance limitations. An overloaded firewall can cause severe damage to the protected enterprise network, because any legitimate communication through it is either degraded or even completely severed. In this paper, we address how to dynamically balance packet filtering workloads on distributed firewalls efficiently in large enterprise networks. We model dynamic load balancing on distributed firewalls as a minimax optimization problem, and show that it is strongly NP-complete even if we eliminate all precedence relationships among policy rules by rule rewriting. Accordingly, we propose a light-weight rule distribution scheme that quickly balances workloads among all firewalls. Our scheme is adaptive to incoming traffic. Moreover, dynamically placing and ordering policy rules on distributed firewalls reduces the probability that attackers successfully infer the rule distribution. Experimental results show that using a commodity PC, our approach can reduce the peak firewall workload in distributed firewall systems by 40% within less than five minutes, compared against alternative solutions that only optimize rule ordering on individual firewalls.
引用
收藏
页码:229 / +
页数:2
相关论文
共 50 条
  • [1] A multi-platform toolkit for the configuration of packet-filtering firewalls
    Prandini, Marco
    Proceedings of the IASTED International Conference on Communication, Network, and Information Security, 2005, : 146 - 153
  • [2] Adaptive Early Packet Filtering for Defending Firewalls against DoS Attacks
    El-Atawy, Adel
    Al-Shaer, Ehab
    Tran, Tung
    Boutaba, Raouf
    IEEE INFOCOM 2009 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, VOLS 1-5, 2009, : 2437 - +
  • [3] UDP State Manipulation: Description of a Packet Filtering Vulnerability in Stateful Firewalls
    Koribeche, Wassim
    Espes, David
    Morin, Cedric
    FOUNDATIONS AND PRACTICE OF SECURITY, PT I, FPS 2023, 2024, 14551 : 302 - 317
  • [4] Improving distributed firewalls performance through vertical load balancing
    Paul, O
    NETWORKING 2004: NETWORKING TECHNOLOGIES, SERVICES, AND PROTOCOLS; PERFORMANCE OF COMPUTER AND COMMUNICATION NETWORKS; MOBILE AND WIRELESS COMMUNICATIONS, 2004, 3042 : 25 - 37
  • [5] The Security Technology of E-commence——Intelligent Packet-filtering Firewalls
    WU Jin-lin 1
    2. Computer Science Department
    厦门大学学报(自然科学版), 2002, (S1) : 277 - 277
  • [6] On dynamic optimization of packet matching in high-speed firewalls
    Hamed, Hazem
    El-Atawy, Adel
    Al-Shaer, Ehab
    IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2006, 24 (10) : 1817 - 1830
  • [7] Balancing Workloads of Servers Maintaining Scalable Distributed Data Structures
    Lukawski, Grzegorz
    Sapiecha, Krzysztof
    PROCEEDINGS OF THE 19TH INTERNATIONAL EUROMICRO CONFERENCE ON PARALLEL, DISTRIBUTED, AND NETWORK-BASED PROCESSING, 2011, : 80 - 84
  • [8] Design and Implementation of an Automated Dynamic Rule System for Distributed Firewalls
    Tudosi, Andrei-Daniel
    Graur, Adrian
    Balan, Doru Gabriel
    Potorac, Alin Dan
    Tarabuta, Radu-Cezar
    ADVANCES IN ELECTRICAL AND COMPUTER ENGINEERING, 2023, 23 (03) : 29 - 38
  • [9] Optimizing Distributed Load Balancing for Workloads with Time-Varying Imbalance
    Lifflander, Jonathan
    Slattengren, Nicole Lemaster
    Pebay, Philippe P.
    Miller, Phil
    Rizzi, Francesco
    Bettencourt, Matthew T.
    2021 IEEE INTERNATIONAL CONFERENCE ON CLUSTER COMPUTING (CLUSTER 2021), 2021, : 238 - 249
  • [10] Dynamic load balancing without packet reordering
    Kandula, Srikanth
    Katabi, Dina
    Sinha, Shantanu
    Berger, Arthur
    Computer Communication Review, 2007, 37 (02): : 51 - 62