首页> 外文会议> >Barbarians in the Gate: An Experimental Validation of NIC-based Distributed Firewall Performance and Flood Tolerance
【24h】

Barbarians in the Gate: An Experimental Validation of NIC-based Distributed Firewall Performance and Flood Tolerance

机译:野蛮人:基于NIC的分布式防火墙性能和耐洪能力的实验验证

获取原文

摘要

This paper presents our experience validating the flood tol- erance of two network interface card (NIC)-based embedded firewall solutions, the Embedded Firewall (EFW) and the Au- tonomic Distributed Firewall (ADF). Experiments were per- formed for both embedded firewall devices to determine their flood tolerance and performance characteristics. The results show that both are vulnerable to packet flood attacks on a 100 Mbps network. In certain configurations, we found that both embedded firewall devices can have a significant, negative impact on bandwidth and application performance. These re- sults imply first that, firewall rule-sets should be optimized for performance-sensitive applications, and second, that proper consideration must be given to attack risks and mitigations before either the EFW or ADF is deployed. Finally, we be- lieve that future embedded firewall implementations should be vetted in a manner similar to that presented in this paper. Our experience shows that when their limitations are properly considered, both the EFW and ADF can be safely deployed to enhance network security without undue risk.
机译:本文介绍了我们在验证两种基于网络接口卡(NIC)的嵌入式防火墙解决方案,嵌入式防火墙(EFW)和自动分布式防火墙(ADF)的泛洪能力方面的经验。对这两种嵌入式防火墙设备都进行了实验,以确定它们的洪泛容忍度和性能特征。结果表明,两者都容易受到100 Mbps网络上的数据包泛洪攻击的影响。在某些配置中,我们发现两个嵌入式防火墙设备都可能对带宽和应用程序性能产生重大的负面影响。这些结果表明,首先,应针对性能敏感的应用程序优化防火墙规则集,其次,在部署EFW或ADF之前,必须适当考虑攻击风险和缓解措施。最后,我们相信,未来的嵌入式防火墙实现应以与本文介绍的方式类似的方式进行审查。我们的经验表明,如果适当考虑了它们的局限性,则可以安全地部署EFW和ADF,以增强网络安全性而不会造成不适当的风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号