Dynamic balancing of packet filtering workloads on distributed firewalls

被引:0
|
作者
Yan, Guanhua [1 ]
Chen, Songqing [2 ]
Eidenbenz, Stephan [1 ]
机构
[1] Los Alamos Natl Lab, Informat Sci CCS 3, Los Alamos, NM 87545 USA
[2] George Mason Univ, Dept Comp Sci, Fairfax, VA 22030 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Firewalls are widely deployed nowadays to enforce security policies of enterprise networks. While having played crucial roles in securing these networks, firewalls themselves are subject to performance limitations. An overloaded firewall can cause severe damage to the protected enterprise network, because any legitimate communication through it is either degraded or even completely severed. In this paper, we address how to dynamically balance packet filtering workloads on distributed firewalls efficiently in large enterprise networks. We model dynamic load balancing on distributed firewalls as a minimax optimization problem, and show that it is strongly NP-complete even if we eliminate all precedence relationships among policy rules by rule rewriting. Accordingly, we propose a light-weight rule distribution scheme that quickly balances workloads among all firewalls. Our scheme is adaptive to incoming traffic. Moreover, dynamically placing and ordering policy rules on distributed firewalls reduces the probability that attackers successfully infer the rule distribution. Experimental results show that using a commodity PC, our approach can reduce the peak firewall workload in distributed firewall systems by 40% within less than five minutes, compared against alternative solutions that only optimize rule ordering on individual firewalls.
引用
收藏
页码:229 / +
页数:2
相关论文
共 50 条
  • [41] Dynamic load balancing for distributed network management
    Yoshihara, K
    Isomura, M
    Horiuchi, H
    INTEGRATED NETWORK MANAGEMENT VIII: MANAGING IT ALL, 2003, 118 : 277 - 290
  • [42] Dynamic Load Balancing Algorithms for Distributed Networks
    Thejovathi, M.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2014, 14 (02): : 125 - 134
  • [43] Dynamic Load Balancing Algorithm of Distributed Systems
    Kirichenko, Lyudmila
    Ivanisenko, Igor
    Radivilova, Tamara
    2016 13TH INTERNATIONAL CONFERENCE ON MODERN PROBLEMS OF RADIO ENGINEERING, TELECOMMUNICATIONS AND COMPUTER SCIENCE (TCSET), 2016, : 515 - 518
  • [44] On the stability of a distributed dynamic load balancing algorithm
    Cortés, A
    Ripoll, A
    Senar, MA
    Cedó, F
    Luque, E
    1998 INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS, PROCEEDINGS, 1998, : 435 - 446
  • [45] Genetic scheme for distributed dynamic load balancing
    Munemoto, M.
    Takai, Y.
    Sato, Y.
    Bulletin of the Faculty of Engineering - Hokkaido University, 1994, (167):
  • [46] Synchronous distributed load balancing on dynamic networks
    Bahi, J
    Couturier, R
    Vernier, F
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2005, 65 (11) : 1397 - 1405
  • [47] DYNAMIC LOAD BALANCING FOR DISTRIBUTED MEMORY MULTIPROCESSORS
    CYBENKO, G
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 1989, 7 (02) : 279 - 301
  • [48] Dynamic load balancing in distributed hash tables
    Bienkowski, M
    Korzeniowski, M
    der Heide, FMA
    PEER-TO-PEER SYSTEMS IV, 2005, 3640 : 217 - 225
  • [49] Dynamic load balancing in distributed multimedia systems
    Hieaiwa, A
    Komatsu, N
    Komiya, K
    Ikeda, H
    40TH MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS, VOLS 1 AND 2, 1998, : 650 - 653
  • [50] Distributed dynamic load balancing in wireless networks
    Borst, Sem
    Saniee, Iraj
    Whiting, Phil
    MANAGING TRAFFIC PERFORMANCE IN CONVERGED NETWORKS, 2007, 4516 : 1024 - +