Dynamic balancing of packet filtering workloads on distributed firewalls

被引:0
|
作者
Yan, Guanhua [1 ]
Chen, Songqing [2 ]
Eidenbenz, Stephan [1 ]
机构
[1] Los Alamos Natl Lab, Informat Sci CCS 3, Los Alamos, NM 87545 USA
[2] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls are widely deployed nowadays to enforce security policies of enterprise networks. While having played crucial roles in securing these networks, firewalls themselves are subject to performance limitations. An overloaded firewall can cause severe damage to the protected enterprise network, because any legitimate communication through it is either degraded or even completely severed. In this paper, we address how to dynamically balance packet filtering workloads on distributed firewalls efficiently in large enterprise networks. We model dynamic load balancing on distributed firewalls as a minimax optimization problem, and show that it is strongly NP-complete even if we eliminate all precedence relationships among policy rules by rule rewriting. Accordingly, we propose a light-weight rule distribution scheme that quickly balances workloads among all firewalls. Our scheme is adaptive to incoming traffic. Moreover, dynamically placing and ordering policy rules on distributed firewalls reduces the probability that attackers successfully infer the rule distribution. Experimental results show that using a commodity PC, our approach can reduce the peak firewall workload in distributed firewall systems by 40% within less than five minutes, compared against alternative solutions that only optimize rule ordering on individual firewalls.
引用
收藏
页码:229 / +
页数:2
相关论文
共 50 条
  • [31] Centralized administration of distributed firewalls
    Miller, M
    Morris, J
    PROCEEDINGS OF THE TENTH SYSTEMS ADMINISTRATION CONFERENCE (LISA X), 1996, : 19 - 23
  • [32] Static and dynamic packet filtering on lightly managed systems
    Lupo, James
    Likarish, Daniel
    3RD INTERNATIONAL CONFERENCE ON INFORMATION WARFARE AND SECURITY, PROCEEDINGS, 2008, : 263 - 268
  • [33] The Importance of Dynamic Load Balancing among OpenMP Thread Teams for Irregular Workloads
    Xiao, Xiong
    Hirasawa, Shoichi
    Takizawa, Hiroyuki
    Kobayashi, Hiroaki
    2016 FOURTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING (CANDAR), 2016, : 529 - 535
  • [34] AuDy: Automatic Dynamic Least-Weight Balancing for Stream Workloads Scalability
    Martins, Pedro
    Abbasi, Maryam
    Furtado, Pedro
    2014 IEEE INTERNATIONAL CONGRESS ON BIG DATA (BIGDATA CONGRESS), 2014, : 176 - 183
  • [35] Distributed Weight Balancing under Integer Constraints in the Presence of Packet Drops
    Rikos, Apostolos I.
    Hadjicostis, Christoforos N.
    2017 IEEE 56TH ANNUAL CONFERENCE ON DECISION AND CONTROL (CDC), 2017,
  • [36] Load balancing a cluster of Web servers: Using distributed packet rewriting
    Aversa, Luis
    Bestavros, Azer
    IEEE International Performance, Computing and Communications Conference, Proceedings, 2000, : 24 - 29
  • [37] Analysis and Filtering of Network Communication in ISP Firewalls
    Ocenasek, Pavel
    Sveda, Miroslav
    2012 THIRD INTERNATIONAL CONFERENCE ON THEORETICAL AND MATHEMATICAL FOUNDATIONS OF COMPUTER SCIENCE (ICTMF 2012), 2013, 38 : 491 - 494
  • [38] Scalability of Distributed Dynamic Load Balancing Mechanisms
    Calsavara, Alcides
    Lima, Luiz A. P., Jr.
    PROCEEDINGS OF THE TENTH INTERNATIONAL CONFERENCE ON NETWORKS (ICN 2011), 2011, : 347 - 352
  • [39] Public review for dynamic load balancing without packet reordering
    Roughan, Matthew
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2007, 37 (02) : 51 - 51