메뉴 건너뛰기
.. 내서재 .. 알림
소속 기관/학교 인증
인증하면 논문, 학술자료 등을  무료로 열람할 수 있어요.
한국대학교, 누리자동차, 시립도서관 등 나의 기관을 확인해보세요
(국내 대학 90% 이상 구독 중)
로그인 회원가입 고객센터 ENG
주제분류

추천
검색

논문 기본 정보

자료유형
학술저널
저자정보
저널정보
SK텔레콤 Telecommunications Review Telecommunications Review 제13권 제2호
발행연도
2003.1
수록면
257 - 269 (13page)

이용수

표지
📌
연구주제
📖
연구배경
🔬
연구방법
🏆
연구결과
AI에게 요청하기
추천
검색

초록· 키워드

오류제보하기
Since no single provider can deliver consistent performance, enterprise networks increasingly leverage path diversity through multi-homing. Today, multi-homed non-transit autonomous systems (ASes) surpass single-homed networks in number. In this paper, we address an inevitable problem that occurs when multi-homed networks deploy firewalls in their border. The absolute majority of today's firewalls are so called stateful inspection firewalls, where connection state is exploited for fine-grained control. However, stateful inspection has a topological restriction such that outgoing and incoming traffic of a connection should pass through a single firewall to have desired packet filtering operation. Unfortunately, BGP policies provide very coarse control over the communication paths, and asymmetric routing for multi-homed networks is a real possibility. This mismatch between the requirement and the reality, therefore, can lead to failed connection establishments. In this paper, we formulate the aforementioned phenomenon into a state-sharing problem among multiple firewalls under asymmetric routing condition. Then we propose a stateful inspection protocol that solves the problem with minimal processing and messaging overhead. Our proposed protocol executes in two phases: 1) Generation of TCP SYN cookie marked with the firewall identification number upon SYN packet arrival, and 2) State sharing triggered by SYN/ACK packet arrival in the absence of a corresponding SYN. We demonstrate that this protocol is scalable, robust, correctly works under any client-server configurations, and simple enough to be deployed for high speed packet filtering. Last but not least, we present a prototype implementation.

목차

등록된 정보가 없습니다.

참고문헌 (0)

참고문헌 신청

함께 읽어보면 좋을 논문

논문 유사도에 따라 DBpia 가 추천하는 논문입니다. 함께 보면 좋을 연관 논문을 확인해보세요!

이 논문의 저자 정보

최근 본 자료

전체보기

댓글(0)

0