loading...
Firewall placement in a large network topology
Tunis, TUNISIA October 29-October 31
DOI Bookmark: http://doi.ieeecomputersociety.org/10.1109/FTDCS.1997.6447016th IEEE Workshop on Future Trends of ...
 This Article 
 
PDF
HTML
 
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
R.N. Smith, Dept. of Comput. Sci. & Eng., Arizona State Univ., Tempe, AZ, USA
S. Bhattacharya, Dept. of Comput. Sci. & Eng., Arizona State Univ., Tempe, AZ, USA
Network security is an integral component of a multi-user distributed information environment. Firewall (FW) technology is a popular approach to build secure networks, and a plethora of FWs have been designed. Our research focuses on the placement of FWs (i.e. an operations research approach) in a large, complex network system, or a system of systems. A key contribution of this research is to propose the concept of a FW cascade, i.e. a chain of FWs, which could be placed in the path between a potential attack point and a network node with sensitive data. Among other benefits, the FW cascade offers two key benefits: (1) increased comprehensiveness (viz. address, port, service, user ID and direction) of security protection; and (2) most importantly, enhancing the degree of confidence that the network security engineer could expect from the underlying set of FWs and the overall end-to-end security protection that is achieved. This results in a novel capability, where a network security engineer can provide completeness and high confidence in the security attributes across the network. We propose a decomposition of the security characters of a FW and a suite of FW placement heuristics which allows us to place the FWs across the network while optimizing cost and maximizing security protection. Minimization of delay is another optimization goal. Performance is depicted using simulation.
Index Terms:
authorisation; firewall placement heuristics; large network topology; network security; multi-user distributed information environment; operations research; firewall cascade; potential attack point; sensitive data; comprehensive security protection; confidence degree; end-to-end security protection; completeness; cost optimization; delay minimization; performance; simulation
Citation:
R.N. Smith, S. Bhattacharya, "Firewall placement in a large network topology," ftdcs, pp.40, 6th IEEE Workshop on Future Trends of Distributed Computing Systems (FTDCS '97), 1997
Usage of this product signifies your acceptance of the Terms of Use.