Crosslayer firewall interaction as a means to provide effective and efficient protection at mobile devices

被引:0
|
作者
Langendoerfer, Peter
Piotrowski, Krzysztof
Peter, Steffen
Lehmann, Martin
机构
[1] IHP, D-15236 Frankfurt, Oder, Germany
[2] DFS Deutsch Flugsicherung GmbH, Langen, SH IR, D-63225 Langen, Germany
关键词
firewall management plane; crosslayer interaction; XML; MAC firewall; mobile devices;
D O I
10.1016/j.comcom.2007.01.019
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
in this paper, we discuss packet filtering firewalls and an application level gateway approach used to secure handheld devices. We propose a firewall management plane as a means for crosslayer interaction. In our approach the application level gateway updates the firewall rules based on its knowledge about whether or not a certain source is sending malicious packets. Hereby, we pursue a policy of removing malicious packets as close as possible to the network interface. We show that in case of secure web service such a crosslayer interaction can significantly decrease the CPU load in case of attacks, i.e., if many malicious packets arrive at the handheld device. Our measurement results show that our crosslayer approach can reduce the CPU load caused by the application layer gateway by about 10-30%. Finally, we propose an integrated firewall processing approach that promises further improvements. It integrates the application controlled firewall before the MAC and provides crosslayer mechanisms to reduce the performance issues of traditional firewall approaches. (c) 2007 Elsevier B.V. All rights reserved.
引用
收藏
页码:1487 / 1497
页数:11
相关论文
共 5 条