Skip to content
Home
About Us
Resources
Profiles Metrics
Authors Directory
Institutions Directory
Top Authors
Top Institutions
Top Sponsors
AI Digest
Contact Us
Menu
Home
About Us
Resources
Profiles Metrics
Authors Directory
Institutions Directory
Top Authors
Top Institutions
Top Sponsors
AI Digest
Contact Us
Home
About Us
Resources
Profiles Metrics
Authors Directory
Institutions Directory
Top Authors
Top Institutions
Top Sponsors
AI Digest
Contact Us
Menu
Home
About Us
Resources
Profiles Metrics
Authors Directory
Institutions Directory
Top Authors
Top Institutions
Top Sponsors
AI Digest
Contact Us
Publication Details
AFRICAN RESEARCH NEXUS
SHINING A SPOTLIGHT ON AFRICAN RESEARCH
computer science
Performance modeling and analysis of network firewalls
IEEE Transactions on Network and Service Management, Volume 9, No. 1, Article 6112159, Year 2012
Notification
URL copied to clipboard!
Description
Network firewalls act as the first line of defense against unwanted and malicious traffic targeting Internet servers. Predicting the overall firewall performance is crucial to network security engineers and designers in assessing the effectiveness and resiliency of network firewalls against DDoS (Distributed Denial of Service) attacks as those commonly launched by today's Botnets. In this paper, we present an analytical queueing model based on the embedded Markov chain to study and analyze the performance of rule-based firewalls when subjected to normal traffic flows as well as DoS attack flows targeting different rule positions. We derive equations for key features and performance measures of engineering and design significance. These features and measures include throughput, packet loss, packet delay, and firewall's CPU utilization. In addition, we verify and validate our analytical model using simulation and real experimental measurements. © 2011 IEEE.
Authors & Co-Authors
Salah, Khaled H.
United Arab Emirates, Abu Dhabi
Khalifa University of Science and Technology
Elbadawi, Khalid
United States, Chicago
Depaul University
Boutaba, Raouf
Canada, Waterloo
David R. Cheriton School of Computer Science
South Korea, Pohang
Pohang University of Science and Technology
Statistics
Citations: 86
Authors: 3
Affiliations: 4
Identifiers
Doi:
10.1109/TNSM.2011.122011.110151
ISSN:
19324537