首页> 外文会议>Internatonal Conference on Computer Communications and Networks >Policy Distribution Methods for Function Parallel Firewalls
【24h】

Policy Distribution Methods for Function Parallel Firewalls

机译:函数并行防火墙的策略分配方法

获取原文

摘要

Parallel firewalls offer a scalable low latency design for inspecting packets at high speeds. Typically consisting of an array of m firewalls, these systems filter arriving packets according to a security policy. Given the firewall array, the rules can be distributed in two fashions. Data parallel copies the entire policy to each firewall and distributes packets. In contrast, function parallel distributes the rules and duplicates packets. The function parallel design can provide significantly lower delays than an equivalent data parallel design, however performance is dependent on how the rules are distributed. Therefore, policy management is vital to the performance of the function parallel firewall system. This paper will describe the guidelines necessary to maintain policy integrity, which guarantees that a function parallel and a traditional firewall provide the same action for a packet. Based on these requirements, a policy can be divided into autonomous chains (sub-policies) that can be distributed across the firewall array. Although determining the optimal distribution will be shown to be NP-hard, an effective algorithm will be described. Simulation results will indicate the distribution algorithm can provide an 86% reduction in the average processing delay as compared to previous distribution methods.
机译:并行防火墙提供可扩展的低延迟设计,用于以高速检查数据包。通常由M个防火墙数组组成,这些系统根据安全策略过滤到达数据包。鉴于防火墙阵列,规则可以以两种方式分发。数据并行将整个策略复制到每个防火墙并分发数据包。相比之下,函数并行分发规则和重复数据包。函数并行设计可以提供比等效数据并行设计的显着较低的延迟,但性能取决于规则的分布方式。因此,策略管理对于函数并行防火墙系统的性能至关重要。本文将描述维护策略完整性所需的准则,这保证了一个并行函数和传统防火墙为数据包提供相同的操作。基于这些要求,可以将策略分为可在防火墙阵列中分布的自动链(子策略)。虽然确定最佳分布将显示为NP - 硬,但将描述有效的算法。与先前的分布方法相比,仿真结果指示分布算法可以在平均处理延迟中减少86%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号