• DocumentCode
    3070916
  • Title

    A stateful CSG-based distributed firewall architecture for robust distributed security

  • Author

    Ramsurrun, V. ; Soyjaudah, K.M.S.

  • Author_Institution
    Electr.&Electron. Eng. Dept., Univ. of Mauritius (UoM), Reduit
  • fYear
    2009
  • fDate
    5-10 Jan. 2009
  • Firstpage
    1
  • Lastpage
    10
  • Abstract
    Distributed firewalls have been developed in order to provide networks with a higher level of protection than traditional firewalling mechanisms like gateway and host-based firewalls. Although distributed firewalls provide higher security, they too have limitations. This work presents the design & implementation of a new distributed firewall model, based on stateful Cluster Security Gateway (CSG) architecture, which addresses those shortcomings. This distributed security model adopts a bottom-up approach such that each cluster of end-user hosts is first secured using the CSG architecture. These different CSGs are then centrally managed by the Network Administrator. A file-based firewall update mechanism is used for dynamic real-time security. IPsec is used to secure the firewall policy update distribution while X.509 certificates cater for sender/receiver authentication. The major benefits of this approach to distributed security include tamper resistance, anti-spoofing, anti-sniffing, secure real-time firewall updating, low overall network load, high scalability and low firewall convergence times.
  • Keywords
    authorisation; distributed processing; cluster security gateway architecture; distributed firewall architecture; dynamic real-time security; file-based firewall update mechanism; firewall policy update distribution; network administrator; receiver authentication; robust distributed security; sender authentication; Authentication; Convergence; Filtering; Load management; Protection; Prototypes; Robustness; Scalability; Security; Software prototyping; Layer 2 per-packet load balancing; distributed cluster security; distributed firewall; stateful CSG architecture;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communication Systems and Networks and Workshops, 2009. COMSNETS 2009. First International
  • Conference_Location
    Bangalore
  • Print_ISBN
    978-1-4244-2912-7
  • Electronic_ISBN
    978-1-4244-2913-4
  • Type

    conf

  • DOI
    10.1109/COMSNETS.2009.4808875
  • Filename
    4808875