首页> 外文期刊>IEEE Transactions on Knowledge and Data Engineering >Cascade of distributed and cooperating firewalls in a secure data network
【24h】

Cascade of distributed and cooperating firewalls in a secure data network

机译:安全数据网络中的分布式防火墙和协作防火墙的级联

获取原文
获取原文并翻译 | 示例
       

摘要

Security issues are critical in networked information systems, e.g., with financial information, corporate proprietary information, contractual and legal information, human resource data, medical records, etc. The paper addresses such diversity of security needs among the different information and resources connected over a secure data network. Installation of firewalls across the data network is a popular approach to providing a secure data network. However, single, individual firewalls may not provide adequate security protection to meet the users needs. The cost of super firewalls, design flaws, as well as implementation inappropriateness with such firewalls may retain security loopholes. The idea proposed is to introduce a cascade of (potentially simpler and less expensive) firewalls in the secure data network, where, between the attacker node and the attacked node, multiple firewalls are expected to provide an added degree of protection. This approach, broadly following the theme of redundancy in engineering systems' design, will increase the confidence and provide more completeness in the level of security protection by the firewalls. The cascade of (i.e., multiple) firewalls can be placed across the secure data network in many ways, not all of which are equally attractive from cost and end-to-end delay perspectives. Toward this, we present heuristics for placement of these firewalls across the different nodes and links of the network in a way that different users can have the level of security they individually need, without having to pay added hardware costs or excess network delay. Three metrics are proposed to evaluate these heuristics: cost, delay, and reduction of attacker's traffic. Performance of these heuristics is presented using simulation, along with some early analytical results. Our research also extends the firewall technology into the well-known advantages of distributed firewalls. Furthermore, the distributed firewalls can be designed to cooperate and stop an attacker's traffic closest to the attack point, thereby reducing the amount of hacker's traffic into the network.
机译:安全问题在网络信息系统中至关重要,例如财务信息,公司专有信息,合同和法律信息,人力资源数据,病历等。本文解决了通过网络连接的不同信息和资源之间的这种安全需求多样性。安全数据网络。在数据网络上安装防火墙是一种提供安全数据网络的流行方法。但是,单个单独的防火墙可能无法提供足够的安全保护来满足用户需求。超级防火墙的成本,设计缺陷以及此类防火墙的实施不当之处可能会保留安全漏洞。提出的想法是在安全数据网络中引入级联的防火墙(可能更简单,更便宜),其中,在攻击者节点和被攻击节点之间,多个防火墙有望提供更高的保护等级。这种方法大致遵循工程系统设计中的冗余主题,将提高防火墙的置信度并提供更完整的安全保护级别。可以多种方式将级联(即多个)防火墙放置在安全数据网络上,从成本和端到端延迟的角度来看,并不是所有的防火墙都具有同样的吸引力。为此,我们提出了在不同节点和网络链路上放置这些防火墙的试探法,以使不同的用户可以获得他们各自需要的安全级别,而不必支付额外的硬件成本或过多的网络延迟。提出了三个指标来评估这些启发式方法:成本,延迟和减少攻击者的流量。这些启发式算法的性能通过仿真以及一些早期分析结果来展示。我们的研究还将防火墙技术扩展到分布式防火墙的众所周知的优势。此外,可以将分布式防火墙设计为协作并阻止最接近攻击点的攻击者流量,从而减少黑客进入网络的流量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号