Abstract

The goal of packet filtering in firewall technology is to sort packets based on packet characteristics. This paper represents the survey on various working models of packet filtering in firewall technology.

Highlights

  • Firewalls performs only very basic operations, such as examining the packet header, verifying the IP address

  • By preferentially filtering out packets that are inscribed with the marks of “infected” edges, the proposed scheme removes most of the Distributed Denial of Service (DDoS) traffic while affecting legitimate traffic only slightly

  • Simulation results based on real-world network topologies all demonstrate that the proposed technique can improve the throughput of legitimate traffic by three to seven times during DDoS attacks [2]

Read more

Summary

Packet Filtering

2.2 On Dynamic Optimization of Packet Matching in High-Speed Firewalls : This paper has twofold They presented a novel algorithm for maximizing early rejection of unwanted flows with minimal impact on other flows. Linux iptables is a reputed secure stateful packet filter firewall package, it has some weaknesses This package can not detect or control all peer-to-peer connections. For controlling peer-to-peer connections investigator blocked some peer-to-peer well known static ports with Linux iptables and for increasing the control of other peer-to-peer applications which used dynamic ports, he used QOS rules. This trend could drop most of peer-to-peer connections and save internet bandwidth, it was not the complete solution. He decided to control peer-to peer connections by implementing a new module which checks peer-to-peer payloads in his investigation[4]

Discriminative Wavelet Packet Filter Bank Selection for Pattern Recognition
SPAF: Stateless FSA-Based Packet Filters
Modeling Filtering Predicates Composition with Finite State Automata
Rule Pattern Parallelization of Packet Filters on Muti-Core Environments
CBF: A Packet Filtering Method for DDoS Attack Defense in Cloud Environment
Model-Based Tool-Assistance for Packet-Filter Design
2.10 The BSD packet filter: a new architecture for user-level packet capture
Conclusion
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call