首页> 外文会议>International Conference on COMmunication Systems And NETworks >A stateful CSG-based distributed firewall architecture for robust distributed security
【24h】

A stateful CSG-based distributed firewall architecture for robust distributed security

机译:用于强大的分布式安全性的基于CSG的分布式防火墙架构

获取原文

摘要

Distributed firewalls have been developed in order to provide networks with a higher level of protection than traditional firewalling mechanisms like gateway and host-based firewalls. Although distributed firewalls provide higher security, they too have limitations. This work presents the design & implementation of a new distributed firewall model, based on stateful Cluster Security Gateway (CSG) architecture, which addresses those shortcomings. This distributed security model adopts a bottom-up approach such that each cluster of end-user hosts is first secured using the CSG architecture. These different CSGs are then centrally managed by the Network Administrator. A file-based firewall update mechanism is used for dynamic real-time security. IPsec is used to secure the firewall policy update distribution while X.509 certificates cater for sender/receiver authentication. The major benefits of this approach to distributed security include tamper resistance, anti-spoofing, anti-sniffing, secure real-time firewall updating, low overall network load, high scalability and low firewall convergence times.
机译:已经开发了分布式防火墙,以便提供比网关和基于主机的防火墙等传统防火墙机制更高的保护级别的网络。虽然分布式防火墙提供更高的安全性,但它们也有局限性。这项工作介绍了一种基于有状态群集安全网关(CSG)架构的新分布式防火墙模型的设计和实现,该架构解决了这些缺点。该分布式安全模型采用自下而上的方法,使得首先使用CSG架构安全地确保每个终端用户主机。然后由网络管理员集中管理这些不同的CSG。基于文件的防火墙更新机制用于动态实时安全性。 IPsec用于确保防火墙策略更新分发,而X.509证书迎合发件人/接收器身份验证。这种方法对分布式安全性的主要优势包括防篡改,防欺骗,防嗅,安全的实时防火墙更新,低整体网络负载,高可扩展性和低防火墙收敛时间。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号