Abstract
Firewalls are important network devices which provide first hand defense against network threat. This level of defense is depended on firewall rules. Traditional firewalls, i.e., Cisco ACL, IPTABLES, Check Point and Juniper NetScreen firewall use listed rule to regulate packet flows. However, the listed rules may lead to rule conflictions which make the firewall to be less secure or even slowdown in performance. Based on our previous research works, we proposed the Tree-Rule firewall which does not encounter such rule conflicts within its rule set and operates faster than the traditional firewalls. However, in big or complex networks, the Tree-Rule firewall still may face two main problems. 1. Firewall administrators may face difficulty to write big and complex rule. 2. Difficulty to select appropriate attribute column for the Root node. In this paper, we propose an improved model for the Tree-Rule firewall by extending our previous models. We offer the use of combination between IN and OUT interfaces of the firewall to separate a big rule to many small independent rules. Each separated rule then can be managed in an individual screen. Sequence of verifying attributes, i.e., Source IP, Destination IP and Destination Port numbers, can be ordered independently in each separated rule. We implement the two main schemes on Linux Cent OS 6.3. We found that the improved Tree-Rule firewall can be managed easily with low processing delay.
Original language | Undefined |
---|---|
Title of host publication | 15th IEEE International Conference on Trust, Security and Privacy in Computing and Communications |
Place of Publication | USA |
Publisher | IEEE Computer Society |
Pages | 178-184 |
Number of pages | 7 |
DOIs | |
Publication status | Published - Aug 2016 |
Event | 15th IEEE International Conference on Trust, Security and Privacy in Computing and Communications 2016 - Tianjin University, Tianjin, China Duration: 23 Aug 2016 → 26 Aug 2016 Conference number: 15 |
Publication series
Name | |
---|---|
Publisher | IEEE Computer Society |
Conference
Conference | 15th IEEE International Conference on Trust, Security and Privacy in Computing and Communications 2016 |
---|---|
Abbreviated title | TrustCom 2016 |
Country/Territory | China |
City | Tianjin |
Period | 23/08/16 → 26/08/16 |
Keywords
- SCS-Cybersecurity
- Large Rule Size
- EWI-27065
- Firewall
- IR-100643
- Low Delay
- Tree-Rule firewall
- METIS-317222
- Network Security