The Experts below are selected from a list of 1230 Experts worldwide ranked by ideXlab platform

Yuan Shihu - One of the best experts on this subject based on the ideXlab platform.

Najbr Ondřej - One of the best experts on this subject based on the ideXlab platform.

  • Adaptive Linux Firewalls, geographic Firewalls
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2009
    Co-Authors: Najbr Ondřej
    Abstract:

    The aim of the Bachelor's thesis is to study and describe the options of adaptive Firewalling, which has a Linux Firewall netfilter, and to study the advanced routing and marginally geographic IP filtering. In detail I will deal with the work with Iptables and its using in creation of Firewalls for the Linux operating system. In the next section in detail I will describe the design and implementation Linux applications of creating rules in Iptables

  • Adaptive Linux Firewalls, geographic Firewalls
    Vysoké učení technické v Brně. Fakulta elektrotechniky a komunikačních technologií, 2009
    Co-Authors: Najbr Ondřej
    Abstract:

    Cílem bakalářské práce je prostudovat a popsat možnosti adaptivního Firewallingu, kterými disponuje Linuxový Firewall netfilter, prostudovat pokročilý routing a okrajově geografický IP filtering. Detailně se budu zabývat prací s IPTABLES a jejím využitím při tvorbě Firewallů pro operační systém Linux. V další části detailně popíši návrh a implementaci Linuxové aplikace pro tvorbu pravidel do IPTABLES.The aim of the Bachelor's thesis is to study and describe the options of adaptive Firewalling, which has a Linux Firewall netfilter, and to study the advanced routing and marginally geographic IP filtering. In detail I will deal with the work with Iptables and its using in creation of Firewalls for the Linux operating system. In the next section in detail I will describe the design and implementation Linux applications of creating rules in Iptables.

Zhang Jianzhong - One of the best experts on this subject based on the ideXlab platform.

Scott Hazelhurst - One of the best experts on this subject based on the ideXlab platform.

  • nfshunt a Linux Firewall with openflow enabled hardware bypass
    2015 IEEE Conference on Network Function Virtualization and Software Defined Network (NFV-SDN), 2015
    Co-Authors: Simeon Miteff, Scott Hazelhurst
    Abstract:

    Data-intensive research computing requires the capability to transfer files over long distances at high throughput. Stateful Firewalls introduce sufficient packet loss to prevent researchers from fully exploiting high bandwidth-delay network links. To work around this challenge, the Science DMZ design trades off stateful packet filtering capability for loss-free forwarding via an ordinary Ethernet switch [1]. We propose a novel extension to the Science DMZ design, which uses an SDN-based Firewall. This paper introduces NFShunt, a Firewall based on Linux's Netfilter combined with OpenFlow switching. Implemented as an OpenFlow 1.0 controller coupled to Netfilter's connection tracking, NFShunt allows the bypass-switching policy to be expressed as part of an iptables Firewall rule-set. Our implementation is described in detail, and latency of the control-plane mechanism is reported. TCP throughput and packet loss is shown at various round-trip latencies, with comparisons to pure switching, as well as to a high-end Cisco Firewall. The results support reported observations regarding Firewall introduced packet-loss, and indicate that the SDN design of NFShunt is a viable approach to enhancing a traditional Firewall to meet the performance needs of data-intensive researchers.

  • NFV-SDN - NFShunt: A Linux Firewall with OpenFlow-enabled hardware bypass
    2015 IEEE Conference on Network Function Virtualization and Software Defined Network (NFV-SDN), 2015
    Co-Authors: Simeon Miteff, Scott Hazelhurst
    Abstract:

    Data-intensive research computing requires the capability to transfer files over long distances at high throughput. Stateful Firewalls introduce sufficient packet loss to prevent researchers from fully exploiting high bandwidth-delay network links. To work around this challenge, the Science DMZ design trades off stateful packet filtering capability for loss-free forwarding via an ordinary Ethernet switch [1]. We propose a novel extension to the Science DMZ design, which uses an SDN-based Firewall. This paper introduces NFShunt, a Firewall based on Linux's Netfilter combined with OpenFlow switching. Implemented as an OpenFlow 1.0 controller coupled to Netfilter's connection tracking, NFShunt allows the bypass-switching policy to be expressed as part of an iptables Firewall rule-set. Our implementation is described in detail, and latency of the control-plane mechanism is reported. TCP throughput and packet loss is shown at various round-trip latencies, with comparisons to pure switching, as well as to a high-end Cisco Firewall. The results support reported observations regarding Firewall introduced packet-loss, and indicate that the SDN design of NFShunt is a viable approach to enhancing a traditional Firewall to meet the performance needs of data-intensive researchers.

Peng Chang - One of the best experts on this subject based on the ideXlab platform.

  • ICCSE - Design and implementation of Linux Firewall based on the frame of Netfilter/IPtable
    2016 11th International Conference on Computer Science & Education (ICCSE), 2016
    Co-Authors: Baoliang Wang, Kaining Lu, Peng Chang
    Abstract:

    With the constant development of network technology today, network not only brings us a convenient and efficient life, and is accompanied by a variety of network security problems. Firewall, as a main way to prevent network attacks, is often used to prevent illegal connection and separates the internal network from the insecure networks, to protect the safety of the Linux systems which used in small and medium-sized enterprise. In this paper, the main content is to complete the function of Firewall which is based on the Linux operating system, using Netfliter as Firewall architecture, and the IPtable as a user space module tool. Firstly, this paper briefly analyzes the Netfilter/IPtable architecture and princIPle and working process of state detection technology, then, configure the Firewall. At the last, the Firewall experiment verified the effectiveness and safety of the design of the Firewall.

  • design and implementation of Linux Firewall based on the frame of netfilter iptable
    International Conference on Computer Science and Education, 2016
    Co-Authors: Baoliang Wang, Peng Chang
    Abstract:

    With the constant development of network technology today, network not only brings us a convenient and efficient life, and is accompanied by a variety of network security problems. Firewall, as a main way to prevent network attacks, is often used to prevent illegal connection and separates the internal network from the insecure networks, to protect the safety of the Linux systems which used in small and medium-sized enterprise. In this paper, the main content is to complete the function of Firewall which is based on the Linux operating system, using Netfliter as Firewall architecture, and the IPtable as a user space module tool. Firstly, this paper briefly analyzes the Netfilter/IPtable architecture and princIPle and working process of state detection technology, then, configure the Firewall. At the last, the Firewall experiment verified the effectiveness and safety of the design of the Firewall.