首页> 外文会议> >An MBone proxy for an application gateway firewall
【24h】

An MBone proxy for an application gateway firewall

机译:应用程序网关防火墙的MBone代理

获取原文

摘要

The Internet's multicast backbone (MBone) holds great potential for many organizations because it supports low-cost audio and video conferencing and carries live broadcasts of an increasing number of public interest events. MBone conferences are transmitted via unauthenticated multicast datagrams, which unfortunately convey significant security vulnerabilities to any system that receives them. For this reason, most application gateway firewalls block MBone datagrams sent from the Internet and prevent them from reaching hosts on internal networks. This paper describes the design and rationale for a new set of facilities for the Trusted Information Systems (TIS) Internet Firewall Toolkit (FWTK). These facilities, which are fully implemented, significantly reduce the security risks of observing or participating in MBone conferences. They impose no functional constraints on MBone applications and are transparent to users. Configuration options that support tradeoffs among security, performance and ease of use are discussed.
机译:互联网的多播骨干网(MBone)对于许多组织来说具有巨大的潜力,因为它支持低成本的音频和视频会议,并可以进行越来越多的公共利益事件的实时广播。 MBone会议是通过未经身份验证的多播数据报传输的,不幸的是,这些数据报将严重的安全漏洞传达给接收它们的任何系统。因此,大多数应用程序网关防火墙会阻止从Internet发送的MBone数据报,并阻止它们到达内部网络上的主机。本文介绍了一组用于可信信息系统(TIS)Internet防火墙工具包(FWTK)的新功能的设计和原理。这些设施已得到充分实施,大大降低了观察或参加MBone会议的安全风险。它们对MBone应用程序没有任何功能上的限制,并且对用户是透明的。讨论了支持在安全性,性能和易用性之间进行折衷的配置选项。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号