FIREWALL RULE SET OPTIMIZATION

Similar documents
2. What is the most cost-effective method of solving interface congestion that is caused by a high level of traffic between two switches?

CCNA 3 Chapter 2 v5.0 Exam Answers 2015 (100%)

CCNA Security v2.0 Chapter 3 Exam Answers

Please contact technical support if you have questions about the directory that your organization uses for user management.

Welcome to Remote Access Services (RAS) Virtual Desktop vs Extended Network. General

Troubleshooting of network problems is find and solve with the help of hardware and software is called troubleshooting tools.

App Orchestration 2.6

NiceLabel LMS. Installation Guide for Single Server Deployment. Rev-1702 NiceLabel

Transmission Control Protocol Introduction

CCNA course contents:

Contents: Module. Objectives. Lesson 1: Lesson 2: appropriately. As benefit of good. with almost any planning. it places on the.

CCNA 1 Chapter v5.1 Answers 100%

BMC Remedyforce Integration with Remote Support

TL 9000 Quality Management System. Measurements Handbook. SFQ Examples

IT Essentials (ITE v6.0) Chapter 8 Exam Answers 100% 2016

BMC Remedyforce Integration with Bomgar Remote Support

EView/400i Management Pack for Systems Center Operations Manager (SCOM)

Tips For Customising Configuration Wizards

2. When logging is used, which severity level indicates that a device is unusable?

Questions and Answers

Performance of VSA in VMware vsphere 5

CCNA Security v2.0 Chapter 9 Exam Answers

CounterSnipe Software Installation Guide Software Version 10.x.x. Initial Set-up- Note: An internet connection is required for installation.

Getting Started with the SDAccel Environment on Nimbix Cloud

VMware AirWatch Certificate Authentication for Cisco IPSec VPN

Using the Swiftpage Connect List Manager

1 Getting and Extracting the Upgrader

Systems & Operating Systems

Firmware Upgrade Wizard v A Technical Guide

Configuring Database & SQL Query Monitoring With Sentry-go Quick & Plus! monitors

Vulnerability Protection A Buffer for Patching

Due Date: Lab report is due on Mar 6 (PRA 01) or Mar 7 (PRA 02)

Link-layer switches. Jurassic Park* LANs with backbone hubs are good. LANs with backbone hubs are bad. Hubs, bridges, and switches

vrealize Operations Management Pack for Storage Devices Release Notes

Retrieval Effectiveness Measures. Overview

Graduate Application Review Process Documentation

PAGE NAMING STRATEGIES

Dolby Conference Phone Support Frequently Asked Questions

Summary. Server environment: Subversion 1.4.6

HP OpenView Performance Insight Report Pack for Quality Assurance

$ARCSIGHT_HOME/current/user/agent/map. The files are named in sequential order such as:

CCNA 3 Chapter 8 v5.0 Exam Answers 2015 (100%) CCNA 5 Page 1

These tasks can now be performed by a special program called FTP clients.

USER MANUAL. RoomWizard Administrative Console

EcoStruxure for Data Centers FAQ

Admin Report Kit for Exchange Server

Dell EqualLogic PS Series Arrays: Expanding Windows Basic Disk Partitions

istartsmart 3.5 Upgrade - Installation Instructions

CS510 Concurrent Systems Class 2. A Lock-Free Multiprocessor OS Kernel

TN How to configure servers to use Optimise2 (ERO) when using Oracle

Cisco Tetration Analytics, Release , Release Notes

SafeDispatch SDR Gateway for MOTOROLA TETRA

DELL EMC VxRAIL vcenter SERVER PLANNING GUIDE

Frequently Asked Questions

VMware EVO:RAIL Customer Release Notes

Launching Xacta 360 Marketplace AMI Guide June 2017

1. What is a characteristic of Frame Relay that provides more flexibility than a dedicated line?

Connect+/SendPro P Series Networking Technical Specification

Software Defined Networking and OpenFlow. Jeffrey Dalla Tezza and Nate Schloss

Report Writing Guidelines Writing Support Services

Stealing passwords via browser refresh

Operational Security. Speaking Frankly The Internet is not a very safe place. A sense of false security... Firewalls*

Using SPLAY Tree s for state-full packet classification

Long Term Project WITS software modernization

The QMF Family V Newsletter 3rd Quarter 2013 Edition

Overview of Data Furnisher Batch Processing

CSE 361S Intro to Systems Software Lab #2

An Introduction to Crescendo s Maestro Application Delivery Platform

ABELDent Platform Setup Conventions

Performance testing. Test approach The below diagram illustrates the approach that is used for performance testing a Pega 7 application.

Max 8/16 and T1/E1 Gateway, Version FAQs

Release Notes. Dell SonicWALL Security firmware is supported on the following appliances: Dell SonicWALL Security 200

The programming for this lab is done in Java and requires the use of Java datagrams.

1 Getting and Extracting the Upgrader

1. The first section examines common performance bottlenecks that need to be considered.

CNS-220-1I: Citrix NetScaler Essentials and Traffic Management

GPA: Plugin for OS Command With Solution Manager 7.1

Xilinx Answer Xilinx PCI Express DMA Drivers and Software Guide

Using the Swiftpage Connect List Manager

TUTORIAL --- Learning About Your efolio Space

HW4 Software version 3. Device Manager and Data Logging LOG-RC Series Data Loggers

Recommended Minimum Requirements for Cisco Meeting Application Web RTC Use

Practical Exercises in Computer Networks and Distributed Systems

Date: October User guide. Integration through ONVIF driver. Partner Self-test. Prepared By: Devices & Integrations Team, Milestone Systems

ABELMed Platform Setup Conventions

How to Guide. DocAve Extender for MOSS 2007 and SPS Installing DocAve Extender and Configuring a Basic SharePoint to Cloud Extension

SAS Viya 3.2 Administration: Mobile Devices

Preparation: Follow the instructions on the course website to install Java JDK and jgrasp on your laptop.

Course Name: VMware vsphere: Install, Configure, Manage [V6.5] Duration: 5 Days

Product Release Notes

Application Note. Digi Connect Wi-SP Troubleshooting Guide. Digi Technical Support 10 May 2016

UDS Enterprise Configuring UDS Enterprise in HA

CNS-222-1I: NetScaler for Apps and Desktops

Studio One 3.5 Audio Dropout Protection and Low-Latency Monitoring

Campuses that access the SFS nvision Windows-based client need to allow outbound traffic to:

Frequently Asked Questions

SW-G using new DryadLINQ(Argentia)

Pupil Book. Unit R082 Creating Digital Graphics PUT YOUR NAME STICKER HERE. OCR Level 1 / 2 Cambridge National Certificate in Creative imedia

AVer IFP Software Release Note Aug

Test Pilot User Guide

Transcription:

Authr Name: Mungle Mukupa Supervisr : Mr Barry Irwin Date : 25 th Octber 2010 Security and Netwrks Research Grup Department f Cmputer Science Rhdes University

Intrductin Firewalls have been and cntinue t be used t implement lgical security between these netwrks f different trust levels. Netwrk speeds have imprved significantly and calls fr better packet filtering. This research fcused n Netwrk layer firewalling.

Prblem Statement Sequential Inspectin: Firewalls inspect packets against a set f rules sequentially until a match is fund. Matching Patterns: Nt all rules are matched each time a packet is inspected thrugh the rule set. Nature f traffic: netwrk traffic is dynamic and ften flws are nt predictable. Netwrk Speed: Increased netwrk speeds are verwhelming firewalls hence the need fr faster filtering decisins by firewalls t avid waste f device and netwrk resurces.

Research Objectives T investigate filtering perfrmance imprvement gained thrugh ptimizing a firewall rule set size. Cme up with a tl that can aid netwrk administratrs in rule set ptimizatin.

Experiment Design The test was perfrmed in virtual envirnment using VmWare sftware and the firewall hst is running in Bridged mde. IP 192.168.46.134 was cnfigured n the bridge c allw remte access frm Linux fr graphical use.

Firewall FreeBSD firewall was used fr tests in this research because f: Flexible rule set lgic First match wins Packet accunting Bridge mde Open surce IPv6 supprt Prted t ther perating systems Mac OS DragnFly Windws

Results Capture IPFW-Graph tl was used t capture filtering actins n bth rule sets. Gives graphic utput f packet matching in real-time. Deny rules shwn in red clur. Allw rules shwn in green clur. Cmbines bth in the all view.

Traffic Traversal Multi prtcl pcap files were sent thrugh the firewall hst running in bridged mde use tw interfaces in different netwrks (Public and Private t simulate the ideal case). Test specific packets were injected int the firewall especially the nes fr testing illegal traffic handling after ptimizing. # nemesis icmp S 209.179.21.76 -D 192.168.46.134 -i 0 -c 0 The cmmand abve tests the firewall s deny actin n icmp.

Rule Sets Default rule set started with a rule set f 37 rules... Passed traffic frm different pcap thrugh the firewall and cllected matching statistics. Nt all rules matched packets inspected: cunter =0. Sme rules did nt match packets ften.

Cunters Lg file

Optimizatin Reducing the rule set size was perfrmed based n the cllected statistics. Frm the initial 37 rules, an ptimized set f 13 rules was created. Hw - cntinued revisin f rule set after several tests using pcap files. Mved frequently matched rules frward Remved nn matching rules Intrduced skip t t skip infrequently matched rules that culd match traffic later. Disabled rules fr services nt available Remving vershadwed rules Aviding redundancy Reintrducing rules fr sme denied packets based n their lg cunt and hw necessary they are deemed.

Perfrmance Tests Nt standardized firewall tests depend n what aspect is being measured This research cncerned itself with thrughput based n rule set size and picked the fllwing metrics as discussin pints: Cnnectin establishment: measured hw fast the firewall created cnnectins per packets inspected cnsidering the number f rules Frwarding rate : cmpared the bits per secnd transmitted n bth rule sets by measuring hw lng it tk fr a full pcap file t be inspected. Cnnectin teardwn: paired with cnnectin establishment, the faster the tear dwn, the less rules a packet is inspected thrugh t find a match. Legal traffic: checked if ptimizatin denied allwed traffic r stpped certain services allwed frm cmmunicating by lking thugh lg file entries. Illegal traffic: checked if ptimizatin allwed false psitives. Tls were used t inject packets denied by a given rule. These values cmbined, were used t determine a gain in filtering speed : THROUGHPUT

Results Tests dne n 1500 bytes pcap file n bth rule sets. Prtcl cmpsitin f pcap file used

OptAid: Tl Design

OptAid Tl Design Cnsidered ffline prcessing and suggesting ptimizatin actins t the administratr. Design questins still t be answered befre OptAid can be implemented: Statistics aggregatin vs. dynamic nature f traffic. Defining triggering cunter threshlds fr ever changing traffic? Hw ften shuld statistics be sent t the database? D we discard rules cmpletely? Hw much verhead des all this intrduce? Anther cnsideratin was t create a sub-rule-set dynamically. Issues faced and being investigated still are: Prcessing cmplicatins with respect t picking rules fr ncming traffic. Hw t wrk ut and tell what flws t adapt fr. Issues with rule numbering when re-sequencing. Hw t apply the sub-rule set t traffic.

Cnclusin Based n the evidence btained frm the tests cnducted in this research, it can be cncluded that: There is a gain in firewall filtering perfrmance by reducing the rule set. Less rules a checked thrugh sequentially and a match is fund faster. The dynamic nature f traffic ffers challenges in adapting rule sets t packet flws. This is why it has generally been described as NP-Hard. Care must be taken nt t pen the netwrk t illegal traffic r denying legitimate traffic by lcking the system ut when ptimizing. Packet filtering is a crucial cmpnent f netwrk security and thus needs better methds t avid wasting f device and netwrk resurces. Better filtering methds and appraches are necessary t make firewalls match up t the imprved transmissin technlgies and netwrk speeds.

Future Wrk Investigate mre n rule set ptimizatin technlgy changes every secnd. Implement OptAid tl having understd and demnstrated matching patterns. Investigate further, perfrmance implicatins with regard t dynamic sub rule set creatin frm the larger set. Add dynamic rule set adaptatin t OptAid nce perfrmance issues are addressed.

Thank yu fr yur attendance