Title :
Performance Modeling and Analysis of Network Firewalls
Author :
Salah, Khaled ; Elbadawi, Khalid ; Boutaba, Raouf
Author_Institution :
Dept. of Comput. Eng., Khalifa Univ. of Sci., Sharjah, United Arab Emirates
fDate :
3/1/2012 12:00:00 AM
Abstract :
Network firewalls act as the first line of defense against unwanted and malicious traffic targeting Internet servers. Predicting the overall firewall performance is crucial to network security engineers and designers in assessing the effectiveness and resiliency of network firewalls against DDoS (Distributed Denial of Service) attacks as those commonly launched by today´s Botnets. In this paper, we present an analytical queueing model based on the embedded Markov chain to study and analyze the performance of rule-based firewalls when subjected to normal traffic flows as well as DoS attack flows targeting different rule positions. We derive equations for key features and performance measures of engineering and design significance. These features and measures include throughput, packet loss, packet delay, and firewall´s CPU utilization. In addition, we verify and validate our analytical model using simulation and real experimental measurements.
Keywords :
Internet; Markov processes; authorisation; computer network security; computer viruses; knowledge based systems; network servers; queueing theory; telecommunication traffic; Botnets; DDoS attacks; DoS attack flows; Internet servers; analytical queueing model; distributed denial of service attacks; embedded Markov chain; firewall CPU utilization; firewall performance; malicious traffic; network firewalls; network security designers; network security engineers; normal traffic flows; packet delay; packet loss; performance measures; performance modeling; rule positions; rule-based firewalls; unwanted traffic; Analytical models; Computer crime; Equations; Kernel; Mathematical model; Queueing analysis; Throughput; Network firewalls; performance analysis; performance modeling; queueing systems;
Journal_Title :
Network and Service Management, IEEE Transactions on
DOI :
10.1109/TNSM.2011.122011.110151