首页> 外文期刊>Network and Service Management, IEEE Transactions on >Performance Modeling and Analysis of Network Firewalls
【24h】

Performance Modeling and Analysis of Network Firewalls

机译:网络防火墙的性能建模和分析

获取原文
获取原文并翻译 | 示例

摘要

Network firewalls act as the first line of defense against unwanted and malicious traffic targeting Internet servers. Predicting the overall firewall performance is crucial to network security engineers and designers in assessing the effectiveness and resiliency of network firewalls against DDoS (Distributed Denial of Service) attacks as those commonly launched by today's Botnets. In this paper, we present an analytical queueing model based on the embedded Markov chain to study and analyze the performance of rule-based firewalls when subjected to normal traffic flows as well as DoS attack flows targeting different rule positions. We derive equations for key features and performance measures of engineering and design significance. These features and measures include throughput, packet loss, packet delay, and firewall's CPU utilization. In addition, we verify and validate our analytical model using simulation and real experimental measurements.
机译:网络防火墙是抵御针对Internet服务器的有害和恶意流量的第一道防线。在评估网络防火墙针对当今僵尸网络通常发起的DDoS(分布式拒绝服务)攻击的有效性和弹性时,预测整体防火墙性能对于网络安全工程师和设计人员至关重要。在本文中,我们提出了一个基于嵌入式马尔可夫链的分析排队模型,以研究和分析基于规则的防火墙在受到正常流量以及针对不同规则位置的DoS攻击流时的性能。我们推导了具有工程和设计意义的关键特征和性能指标的方程式。这些功能和措施包括吞吐量,数据包丢失,数据包延迟和防火墙的CPU使用率。此外,我们使用模拟和实际实验测量来验证和验证我们的分析模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号