An MBone proxy for an application gateway firewall

被引:3
|
作者
Djahandari, K
Sterne, DF
机构
关键词
D O I
10.1109/SECPRI.1997.601318
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet's multicast backbone (MBone) holds great potential for many organizations because it supports low-cost audio and video conferencing and carries live broadcasts of an increasing number of public interest events. MBone conferences are transmitted via unauthenticated multicast datagrams, which unfortunately convey significant security vulnerabilities to any system that receives them. For this reason, most application gateway firewalls block MBone datagrams sent from the Internet and prevent them from reaching hosts on internal networks. This paper describes the design and rationale for a new set of facilities for the TIS Internet Firewall Toolkit (FWTK). These facilities, which are fully implemented, significantly reduce the security risks of observing or participating in MBone conferences. They impose no functional constraints on MBone applications and are transparent to users. Configuration options that support tradeoffs among security, performance, and ease of use are discussed.
引用
收藏
页码:72 / 81
页数:10
相关论文
共 50 条
  • [1] Principle of building an application gateway firewall
    Shi, Lin
    Liu, Jianhui
    Fuxin Kuangye Xueyuan Xuebao (Ziran Kexue Ban)/Journal of Fuxin Mining Institute (Natural Science Edition), 2000, 19 (04): : 404 - 406
  • [3] A secure and transparent firewall web proxy
    Crandell, R
    Clifford, J
    Kent, A
    USENIX ASSOCIATION PROCEEDINGS OF THE SEVENTEENTH LARGE INSTALLATION SYSTEMS ADMINISTRATION CONFERENCE, 2003, : 23 - 30
  • [4] PROGESI: A PROxy Grammar to Enhance Web Application Firewall for SQL Injection Prevention
    Coscia, Antonio
    Dentamaro, Vincenzo
    Galantucci, Stefano
    Maci, Antonio
    Pirlo, Giuseppe
    IEEE ACCESS, 2024, 12 : 107689 - 107703
  • [5] Design and implementation of firewall reverse proxy
    Liu, Yan
    Chen, Hong
    Yang, Yuhang
    Jisuanji Gongcheng/Computer Engineering, 1999, 25 (09): : 66 - 67
  • [6] A hot-failover state machine for gateway services and its application to a Linux firewall
    Roelle, H
    MANAGEMENT TECHNOLOGIES FOR E-COMMERCE AND E-BUSINESS APPLICATIONS, PROCEEDINGS, 2002, 2506 : 181 - 194
  • [7] EGIFM - Extendable Gateway and Industrial Firewall for ModBus
    Tranca, Dumitru-Cristian
    Banu, Calin Iulian
    Rosner, Daniel
    ELEARNING CHALLENGES AND NEW HORIZONS, VOL 4, 2018, : 85 - 92
  • [8] Improving Security of Web-Based Application Using ModSecurity and Reverse Proxy in Web Application Firewall
    Muzaki, Rizki Agung
    Briliyant, Obrina Candra
    Hasditama, Maulana Andika
    Ritchi, Hamzah
    2020 5TH INTERNATIONAL WORKSHOP ON BIG DATA AND INFORMATION SECURITY (IWBIS 2020), 2020, : 89 - 94
  • [9] Research and implementation of cache scheme in a proxy firewall
    Tao, Jing
    Zhao, Long
    Guofang Keji Daxue Xuebao/Journal of National University of Defense Technology, 2002, 24 (06): : 77 - 81
  • [10] Implementation of firewall for web server access management based on application gateway for TNI AD website
    Suryana, M. L. N.
    Muda, N. R. S.
    Minggu, D.
    Agustiady, R.
    Herkariawan, C.
    5TH ANNUAL APPLIED SCIENCE AND ENGINEERING CONFERENCE (AASEC 2020), 2021, 1098