Please use this identifier to cite or link to this item: http://10.1.7.192:80/jspui/handle/123456789/68
Full metadata record
DC FieldValueLanguage
dc.contributor.authorChagela, Vivek N.-
dc.date.accessioned2007-07-06T05:16:44Z-
dc.date.available2007-07-06T05:16:44Z-
dc.date.issued2007-06-01-
dc.identifier.urihttp://hdl.handle.net/123456789/68-
dc.description.abstractFirewalls enforce a security policy between two networks by comparing arriving packets against the policy rules to determine whether they should be accepted or denied. As the amount of data being transferred over networks increases over a time, the firewalls used to protect private networks must process traffic both faster and with greater reliability. In order to cope with new application types like multimedia applications and as high-speed networks become more prevalent, delays will become more significant, new firewall architectures are necessary. The performance of these new architectures is a critical factor because Quality of Service (QoS) demands of such applications have to be satisfied. This thesis covered basics of firewall, which has definitions, types of firewalls, and current firewall approaches. Also as network become complex, managing firewall rules, especially for enterprise networks, has become complex and error-prone. Firewall filtering rules have to be carefully written and organized in order to correctly implement the security policy. In addition, inserting or modifying a filtering rule requires thorough analysis of the relationship between this rule and other rules in order to determine the proper order of this rule and commit the updates for this we presents firewall policies modeling and defined set of anomaly which describes any rules conflicts. This thesis covered single firewall and disturbed firewall architecture implemented using of-the-shelf components like iptables and iproute2. Iptables is a generic table structure that defines rules and commands as part of the netfilter framework that facilitates packet filtering, Network Address Translation, and packet mangling in the Linux 2.4 and later operating systems. Packet mangling is process of modifying packets TOS bits and marking packets before it goes to routing process. Finally, thesis explores the firewall security and performance relationship for single firewall and distributed firewalls. We also discuss the tradeoff between security and performance in terms of delay and throughput vs number of rules in single and distributed firewall.en
dc.language.isoen_USen
dc.publisherInstitute of Technologyen
dc.relation.ispartofseries05MCE003en
dc.subjectComputer 2005en
dc.subjectProject Report 2005en
dc.subjectComputer Project Reporten
dc.subjectProject Reporten
dc.subject05MCEen
dc.subject05MCE003en
dc.titleFirewall: Optimizing Policies, Testing and Performance Evaluationen
dc.typeDissertationen
Appears in Collections:Dissertation, CE

Files in This Item:
File Description SizeFormat 
05MCE003.pdf05MCE0031.64 MBAdobe PDFThumbnail
View/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.