Dynamic balancing of packet filtering workloads on distributed firewalls

被引:0
|
作者
Yan, Guanhua [1 ]
Chen, Songqing [2 ]
Eidenbenz, Stephan [1 ]
机构
[1] Los Alamos Natl Lab, Informat Sci CCS 3, Los Alamos, NM 87545 USA
[2] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls are widely deployed nowadays to enforce security policies of enterprise networks. While having played crucial roles in securing these networks, firewalls themselves are subject to performance limitations. An overloaded firewall can cause severe damage to the protected enterprise network, because any legitimate communication through it is either degraded or even completely severed. In this paper, we address how to dynamically balance packet filtering workloads on distributed firewalls efficiently in large enterprise networks. We model dynamic load balancing on distributed firewalls as a minimax optimization problem, and show that it is strongly NP-complete even if we eliminate all precedence relationships among policy rules by rule rewriting. Accordingly, we propose a light-weight rule distribution scheme that quickly balances workloads among all firewalls. Our scheme is adaptive to incoming traffic. Moreover, dynamically placing and ordering policy rules on distributed firewalls reduces the probability that attackers successfully infer the rule distribution. Experimental results show that using a commodity PC, our approach can reduce the peak firewall workload in distributed firewall systems by 40% within less than five minutes, compared against alternative solutions that only optimize rule ordering on individual firewalls.
引用
收藏
页码:229 / +
页数:2
相关论文
共 50 条
  • [21] Load Balancing and Dynamic Scaling of Cache Storage Against Zipfian Workloads
    Cai, Chris Xiao
    Liang, Guanfeng
    Kozat, Ulas C.
    2014 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2014, : 4208 - 4214
  • [22] COOPERATIVE DISTRIBUTED DYNAMIC LOAD BALANCING
    SHEN, S
    ACTA INFORMATICA, 1988, 25 (06) : 663 - 676
  • [23] Dynamic load balancing for distributed search
    Huston, L
    Nizhner, A
    Pillai, P
    Sukthankar, R
    Steenkiste, P
    Zhang, J
    14th IEEE International Symposium on High Performance Distributed Computing, Proceedings, 2005, : 157 - 166
  • [24] Dynamic Packet Balancing Agent in MANETs based on AOMDV
    Ni, Chen
    Zin, Hyeoncheol
    Lee, Bokman
    Hwang, Dosam
    Kim, Chonggun
    2009 FIRST ASIAN CONFERENCE ON INTELLIGENT INFORMATION AND DATABASE SYSTEMS, 2009, : 362 - 367
  • [25] Optimization of Parallel Firewalls Filtering Rules
    Hadjadj, Taha Elamine
    Tebourbi, Rim
    Bouhoula, Adel
    Ksantini, Riadh
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 515 - 520
  • [26] Optimization of parallel firewalls filtering rules
    Taha Elamine Hadjadj
    Adel Bouhoula
    Rim Tebourbi
    Riadh Ksantini
    International Journal of Information Security, 2022, 21 : 323 - 340
  • [27] Optimization of parallel firewalls filtering rules
    Hadjadj, Taha Elamine
    Tebourbi, Rim
    Bouhoula, Adel
    Ksantini, Riadh
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2022, 21 (02) : 323 - 340
  • [28] Handling anomalies in distributed firewalls
    Bouhoula, Adel
    Trabelsi, Zouheir
    2006 Innovations in Information Technology, 2006, : 237 - 241
  • [29] Distributed Filtering for Markovian Jump Systems with Packet Loss Compensation
    Zhou, Zhidong
    Wu, Yuyan
    Cheng, Jun
    Wang, Yunliang
    INTERNATIONAL JOURNAL OF CONTROL AUTOMATION AND SYSTEMS, 2023, 21 (07) : 2154 - 2161
  • [30] Distributed Filtering for Markovian Jump Systems with Packet Loss Compensation
    Zhidong Zhou
    Yuyan Wu
    Jun Cheng
    Yunliang Wang
    International Journal of Control, Automation and Systems, 2023, 21 : 2154 - 2161