多层防火墙,减轻分布式拒绝服务对网络的影响

Dana Hasan Ahmed, Rebeen Rebwar HamaAmin
{"title":"多层防火墙,减轻分布式拒绝服务对网络的影响","authors":"Dana Hasan Ahmed, Rebeen Rebwar HamaAmin","doi":"10.24271/psr.2022.160803","DOIUrl":null,"url":null,"abstract":"A firewall is one of the key components in securing an organization's network and computational assets against different network and application-based attacks. Most firewall solutions only consider one or two layers of TCP/IP networking architecture to protect against attacks, especially spoofing-based attacks. In contrast, there are some proposed solutions to protect against such attacks. However, these solutions work in areas such as clouds or Software Defined Networks (SDN), and legacy networks cannot utilize such techniques. Therefore, establishing a type of firewall that can be scalable, strong, and easy to implement is a challenge necessary for a new firewall technique to prevail. This paper presents a novel strategy to implement a multi-layered firewall to overcome the current state-of-art firewalls. Our firewall combines a packet-filtering approach (i.e., Internet and Transport layer) with an application layer firewall under the umbrella of Stateful-Packet-Inspection. The experiments were performed in a controlled environment with 1% legitimate packets, and 99% spoofed traffic on average. The Stateful-Packet-Inspection discards any packets based on their traffic flow given to them by the firewall while informing the network administrator about the system breach passively. The results of the experiments are benchmarked with previous works and showed improvement in accuracy by 13.5% and sensitivity by 13.75% while decreasing the false negative rate by 86.5% with minimal computational and network overhead.","PeriodicalId":33835,"journal":{"name":"Passer Journal","volume":" ","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2022-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Multi-layered firewall to mitigate the impact of Distributed Denial of Service on a network\",\"authors\":\"Dana Hasan Ahmed, Rebeen Rebwar HamaAmin\",\"doi\":\"10.24271/psr.2022.160803\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"A firewall is one of the key components in securing an organization's network and computational assets against different network and application-based attacks. Most firewall solutions only consider one or two layers of TCP/IP networking architecture to protect against attacks, especially spoofing-based attacks. In contrast, there are some proposed solutions to protect against such attacks. However, these solutions work in areas such as clouds or Software Defined Networks (SDN), and legacy networks cannot utilize such techniques. Therefore, establishing a type of firewall that can be scalable, strong, and easy to implement is a challenge necessary for a new firewall technique to prevail. This paper presents a novel strategy to implement a multi-layered firewall to overcome the current state-of-art firewalls. Our firewall combines a packet-filtering approach (i.e., Internet and Transport layer) with an application layer firewall under the umbrella of Stateful-Packet-Inspection. The experiments were performed in a controlled environment with 1% legitimate packets, and 99% spoofed traffic on average. The Stateful-Packet-Inspection discards any packets based on their traffic flow given to them by the firewall while informing the network administrator about the system breach passively. The results of the experiments are benchmarked with previous works and showed improvement in accuracy by 13.5% and sensitivity by 13.75% while decreasing the false negative rate by 86.5% with minimal computational and network overhead.\",\"PeriodicalId\":33835,\"journal\":{\"name\":\"Passer Journal\",\"volume\":\" \",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-11-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Passer Journal\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.24271/psr.2022.160803\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Passer Journal","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.24271/psr.2022.160803","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

防火墙是保护组织网络和计算资产免受不同网络和基于应用程序的攻击的关键组件之一。大多数防火墙解决方案只考虑一层或两层TCP/IP网络架构来抵御攻击,尤其是基于欺骗的攻击。相比之下,有一些建议的解决方案可以防止此类攻击。然而,这些解决方案适用于云或软件定义网络(SDN)等领域,而传统网络无法利用这些技术。因此,建立一种可扩展、强大且易于实现的防火墙是新防火墙技术流行所必需的挑战。本文提出了一种实现多层防火墙的新策略,以克服现有技术的防火墙。我们的防火墙将数据包过滤方法(即互联网和传输层)与状态数据包检查保护伞下的应用层防火墙相结合。实验是在受控环境中进行的,平均有1%的合法数据包和99%的欺骗流量。状态数据包检查根据防火墙提供给它们的流量丢弃任何数据包,同时被动地通知网络管理员系统漏洞。实验结果与以前的工作进行了对比,表明在最小的计算和网络开销下,准确度和灵敏度提高了13.5%和13.75%,同时假阴性率降低了86.5%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Multi-layered firewall to mitigate the impact of Distributed Denial of Service on a network
A firewall is one of the key components in securing an organization's network and computational assets against different network and application-based attacks. Most firewall solutions only consider one or two layers of TCP/IP networking architecture to protect against attacks, especially spoofing-based attacks. In contrast, there are some proposed solutions to protect against such attacks. However, these solutions work in areas such as clouds or Software Defined Networks (SDN), and legacy networks cannot utilize such techniques. Therefore, establishing a type of firewall that can be scalable, strong, and easy to implement is a challenge necessary for a new firewall technique to prevail. This paper presents a novel strategy to implement a multi-layered firewall to overcome the current state-of-art firewalls. Our firewall combines a packet-filtering approach (i.e., Internet and Transport layer) with an application layer firewall under the umbrella of Stateful-Packet-Inspection. The experiments were performed in a controlled environment with 1% legitimate packets, and 99% spoofed traffic on average. The Stateful-Packet-Inspection discards any packets based on their traffic flow given to them by the firewall while informing the network administrator about the system breach passively. The results of the experiments are benchmarked with previous works and showed improvement in accuracy by 13.5% and sensitivity by 13.75% while decreasing the false negative rate by 86.5% with minimal computational and network overhead.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
CiteScore
0.50
自引率
0.00%
发文量
23
审稿时长
12 weeks
期刊最新文献
Study of Algal Diatoms in some water resources in Shaglawa District. Erbil, Kurdistan Region of Iraq Antibacterial Efficacy of Extraction of Salvia palaestina Bentham Characterization of biochemical compounds in different accessions of pomegranate (Punica granatum L.) peels in Iraq Lavender Essential Oil in Sanitation on Fertile Egg Exploring efficient techniques to decrease phosphorus levels in previously farmed land to promote the revival of indigenous grassland
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1