Title :
A protocol and simulation for distributed communicating firewalls
Author :
Smith, Robert N. ; Bhattacharya, Sourav
Abstract :
The concept of distributing firewalls into the Internet was previously presented for the purpose of pushing LAN attacks away from a single firewall (R.N. Smith and S. Bhattacharya, 1997; 1999). The paper presents a protocol for firewalls to communicate information to enable distributed firewalls to isolate LAN attacks. Currently firewalls are used to protect a single LAN or extranet of collaborating units. However, each firewall in these configurations are individually managed. Our approach is to place firewalls out into the Internet that will cooperate and push the attack to a firewall that is nearer to the source of the attack. These distributed firewalls can be considered as gateway firewalls. We present a protocol of command and information packets used to take the offensive in the Internet war against hackers and crackers. The communicating firewalls would be placed in routers or switches acting as gateways throughout the Internet. The proposed protocol can be encapsulated as a security agent into any one of the popular router protocols (e.g., BGP and PNNI). We have currently chosen to place our protocol over BGP-4. In order to evaluate our new protocol, we have developed a distributed network protocol simulator which we also describe
Keywords :
Internet; computer network management; digital simulation; local area networks; protocols; security of data; telecommunication computing; BGP; BGP-4; Internet; Internet war; LAN attacks; PNNI; collaborating units; crackers; distributed communicating firewalls; distributed network protocol simulator; gateway firewalls; gateways; hackers; information packets; router protocols; security agent; Authentication; Collaboration; Cryptography; Data security; Extranets; Information security; Internet; Local area networks; Protection; Protocols;
Conference_Titel :
Computer Software and Applications Conference, 1999. COMPSAC '99. Proceedings. The Twenty-Third Annual International
Conference_Location :
Phoenix, AZ
Print_ISBN :
0-7695-0368-3
DOI :
10.1109/CMPSAC.1999.812679