期刊论文详细信息
Future Internet
Principles of Eliminating Access Control Lists within a Domain
John N. Davies1  Paul Comerford2 
[1] Centre for Applied Internet Research (CAIR), Glyndŵr University, Wrexham LL11 2AW, UK;
关键词: routing domain;    performance;    delay through routers;    access control list;    ACL optimization;    off-line verification of ACLs;    firewalls;    inter-firewall optimization;    IP packet filtering;   
DOI  :  10.3390/fi4020413
来源: mdpi
PDF
【 摘 要 】

The infrastructure of large networks is broken down into areas that have a common security policy called a domain. Security within a domain is commonly implemented at all nodes. However this can have a negative effect on performance since it introduces a delay associated with packet filtering. When Access Control Lists (ACLs) are used within a router for this purpose then a significant overhead is introduced associated with this process. It is likely that identical checks are made at multiple points within a domain prior to a packet reaching its destination. Therefore by eliminating ACLs within a domain by modifying the ingress/egress points with equivalent functionality an improvement in the overall performance can be obtained. This paper considers the effect of the delays when using router operating systems offering different levels of functionality. It considers factors which contribute to the delay particularly due to ACLs and by using theoretical principles modified by practical calculation a model is created. Additionally this paper provides an example of an optimized solution which reduces the delay through network routers by distributing the security rules to the ingress/egress points of the domain without affecting the security policy.

【 授权许可】

CC BY   
© 2012 by the authors; licensee MDPI, Basel, Switzerland.

【 预 览 】
附件列表
Files Size Format View
RO202003190044998ZK.pdf 571KB PDF download
  文献评价指标  
  下载次数:11次 浏览次数:13次