• DocumentCode
    2841325
  • Title

    A Function-Parallel Architecture for High-Speed Firewalls

  • Author

    Fulp, Errin W. ; Farley, Ryan J.

  • Author_Institution
    Department of Computer Science, Wake Forest University, Winston-Salem, NC 27109-7311, USA. Email: fulp@wfu.edu
  • Volume
    5
  • fYear
    2006
  • fDate
    38869
  • Firstpage
    2213
  • Lastpage
    2218
  • Abstract
    Firewalls enforce a security policy by inspecting and filtering traffic arriving or departing from a secure network. This is typically done by comparing an arriving packet to a set of rules and performing the matching rule action, which is accept or deny. Unfortunately packet inspections can impose significant delays on traffic due to the complexity and size of policies. Therefore, improving firewall performance is important given the next generation of high-speed networks. This paper introduces a new firewall architecture that can perform packet inspections under increasing traffic loads, higher traffic speeds, and strict QoS requirements. The architecture consists of multiple firewalls configured in parallel that collectively enforce a security policy. Each firewall implements part of the policy and arriving packets are processed by all the firewalls simultaneously. Since multiple firewalls are used to process every packet, the proposed function-parallel system has significantly lower delays (e.g. 74% lower for a four firewall system) and a higher throughput than other data-parallel (load-balancing) firewalls. These findings will be demonstrated empirically. Furthermore unlike data-parallel systems, the function-parallel design allows the stateful inspection of packets, which is critical to prevent certain types of network attacks.
  • Keywords
    Computer architecture; Computer science; Data security; Delay; Filtering; Information security; Inspection; Switches; Telecommunication traffic; Throughput;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2006. ICC '06. IEEE International Conference on
  • Conference_Location
    Istanbul
  • ISSN
    8164-9547
  • Print_ISBN
    1-4244-0355-3
  • Electronic_ISBN
    8164-9547
  • Type

    conf

  • DOI
    10.1109/ICC.2006.255099
  • Filename
    4024494