Detailed Information

Cited 0 time in webofscience Cited 0 time in scopus
Metadata Downloads

A Connection Management Protocol for Stateful Inspection Firewalls in Multi-Homed Networks

Full metadata record
DC Field Value Language
dc.contributor.authorKim, Jin-Ho-
dc.contributor.authorLee, Heejo-
dc.contributor.authorBahk, Saewoong-
dc.date.accessioned2021-09-09T02:07:27Z-
dc.date.available2021-09-09T02:07:27Z-
dc.date.created2021-06-10-
dc.date.issued2008-12-
dc.identifier.issn1229-2370-
dc.identifier.urihttps://scholar.korea.ac.kr/handle/2021.sw.korea/122321-
dc.description.abstractTo provide network services consistently under various network failures, enterprise networks increasingly utilize path diversity through multi-homing. As a result, multi-homed non-transit autonomous systems become to surpass single-homed networks in number. In this paper, we address an inevitable problem that occurs when networks with multiple entry points deploy firewalls in their borders. The majority of today's firewalls use stateful inspection that exploits connection state for fine-grained control. However, stateful inspection has a topological restriction such that outgoing and incoming traffic of a connection should pass through a single firewall to execute desired packet filtering operation. Multi-homed networking environments suffer from this restriction and BGP policies provide only coarse control over communication paths. Due to these features and the characteristics of datagram routing, there exists a real possibility of asymmetric routing. This mismatch between the exit and entry firewalls for a connection causes connection establishment failures. In this paper, we formulate this phenomenon into a state-sharing problem among multiple firewalls tinder asymmetric routing condition. To solve this problem, we propose a stateful inspection protocol that requires very low processing and messaging overhead. Our protocol consists, of the following two phases: 1) Generation of a TCP SYN cookie marked with the firewall identification number upon a SYN packet arrival, and 2) state sharing triggered by a SMACK packet arrival in the absence of the trail (if its initial SYN packet. We demonstrate that our protocol is scalable, robust, and simple enough to be deployed for high speed networks. It also transparently works under any client-server configurations. Last but not least, we present experimental results through a prototype implementation.-
dc.languageEnglish-
dc.language.isoen-
dc.publisherKOREAN INST COMMUNICATIONS SCIENCES (K I C S)-
dc.titleA Connection Management Protocol for Stateful Inspection Firewalls in Multi-Homed Networks-
dc.typeArticle-
dc.contributor.affiliatedAuthorLee, Heejo-
dc.identifier.doi10.1109/JCN.2008.6389863-
dc.identifier.scopusid2-s2.0-58849134931-
dc.identifier.wosid000262763400012-
dc.identifier.bibliographicCitationJOURNAL OF COMMUNICATIONS AND NETWORKS, v.10, no.4, pp.455 - 464-
dc.relation.isPartOfJOURNAL OF COMMUNICATIONS AND NETWORKS-
dc.citation.titleJOURNAL OF COMMUNICATIONS AND NETWORKS-
dc.citation.volume10-
dc.citation.number4-
dc.citation.startPage455-
dc.citation.endPage464-
dc.type.rimsART-
dc.type.docTypeArticle-
dc.identifier.kciidART001311360-
dc.description.journalClass1-
dc.description.journalRegisteredClassscie-
dc.description.journalRegisteredClassscopus-
dc.description.journalRegisteredClasskci-
dc.relation.journalResearchAreaComputer Science-
dc.relation.journalResearchAreaTelecommunications-
dc.relation.journalWebOfScienceCategoryComputer Science, Information Systems-
dc.relation.journalWebOfScienceCategoryTelecommunications-
dc.subject.keywordAuthorConnection management protocol-
dc.subject.keywordAuthormulti-homed networks-
dc.subject.keywordAuthornetwork security-
dc.subject.keywordAuthorrouting asymmetry-
dc.subject.keywordAuthorstateful inspection firewalls-
dc.subject.keywordAuthorSYN cookies-
Files in This Item
There are no files associated with this item.
Appears in
Collections
Graduate School > Department of Computer Science and Engineering > 1. Journal Articles

qrcode

Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.

Related Researcher

Researcher Lee, Hee jo photo

Lee, Hee jo
컴퓨터학과
Read more

Altmetrics

Total Views & Downloads

BROWSE