Scalable Load Balance / High Availability Architecture for Network Security Switch

碩士 === 國立清華大學 === 資訊系統與應用研究所 === 93 === Internet traffic grow very fast in the past years and network security issue becomes more and more critical and important. Typically, network security devices, such as firewalls and Intrusion Detection and Prevention Systems (IPS), are installed behind the rou...

Full description

Bibliographic Details
Main Authors: Yuan-Fang Huang, 黃遠芳
Other Authors: Nen-Fu Huang
Format: Others
Language:en_US
Published: 2005
Online Access:http://ndltd.ncl.edu.tw/handle/27747861150508532801
id ndltd-TW-093NTHU5394036
record_format oai_dc
spelling ndltd-TW-093NTHU53940362016-06-06T04:11:37Z http://ndltd.ncl.edu.tw/handle/27747861150508532801 Scalable Load Balance / High Availability Architecture for Network Security Switch 具延展性且有高可用度和負載平衡機制的網路安全交換機架構 Yuan-Fang Huang 黃遠芳 碩士 國立清華大學 資訊系統與應用研究所 93 Internet traffic grow very fast in the past years and network security issue becomes more and more critical and important. Typically, network security devices, such as firewalls and Intrusion Detection and Prevention Systems (IPS), are installed behind the routers of an enterprise network to prevent the attack from Internet. However, it is found that more than 80% attacks are actually launched from the affected computers inside the intranet. Therefore the concept of defense-in-depth is emerged to prevent attacks not only from the Internet but also from the internal personal computers. This leads the need of security switches to provide the first mile protection. Unfortunately, the current layer-7 security switch solution is complex and expensive. In this thesis, a scalable load balance and high availability (LB/HA) architecture for network security switches is proposed. In this architecture, each “security switch” is composed a traditional layer-2 switch and a “security switch engine (SSE)” which provides the layer-7 packet inspection service. These two components are coupled by Gigabit Ethernet link. A novel mechanism is designed to connect the SSEes so that a group of security switches are interconnected to achieve the HA feature. Thus, the system can still provide security service even only one security switch is alive. An intelligent load balancing is also designed for the SSE so that the security service can be balanced among the SSEes. The proposed architecture is also implemented with four security switches. Experimental results show that the HA function works well for shutting down any three security switches and the security service can be balanced among the alive security switches dynamically. Most importantly, the SSE can be a high performance but cost effective standard IPC, and therefore the proposed LB/HA security system can be implemented on a very cost efficient way. Nen-Fu Huang 黃能富 2005 學位論文 ; thesis 47 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立清華大學 === 資訊系統與應用研究所 === 93 === Internet traffic grow very fast in the past years and network security issue becomes more and more critical and important. Typically, network security devices, such as firewalls and Intrusion Detection and Prevention Systems (IPS), are installed behind the routers of an enterprise network to prevent the attack from Internet. However, it is found that more than 80% attacks are actually launched from the affected computers inside the intranet. Therefore the concept of defense-in-depth is emerged to prevent attacks not only from the Internet but also from the internal personal computers. This leads the need of security switches to provide the first mile protection. Unfortunately, the current layer-7 security switch solution is complex and expensive. In this thesis, a scalable load balance and high availability (LB/HA) architecture for network security switches is proposed. In this architecture, each “security switch” is composed a traditional layer-2 switch and a “security switch engine (SSE)” which provides the layer-7 packet inspection service. These two components are coupled by Gigabit Ethernet link. A novel mechanism is designed to connect the SSEes so that a group of security switches are interconnected to achieve the HA feature. Thus, the system can still provide security service even only one security switch is alive. An intelligent load balancing is also designed for the SSE so that the security service can be balanced among the SSEes. The proposed architecture is also implemented with four security switches. Experimental results show that the HA function works well for shutting down any three security switches and the security service can be balanced among the alive security switches dynamically. Most importantly, the SSE can be a high performance but cost effective standard IPC, and therefore the proposed LB/HA security system can be implemented on a very cost efficient way.
author2 Nen-Fu Huang
author_facet Nen-Fu Huang
Yuan-Fang Huang
黃遠芳
author Yuan-Fang Huang
黃遠芳
spellingShingle Yuan-Fang Huang
黃遠芳
Scalable Load Balance / High Availability Architecture for Network Security Switch
author_sort Yuan-Fang Huang
title Scalable Load Balance / High Availability Architecture for Network Security Switch
title_short Scalable Load Balance / High Availability Architecture for Network Security Switch
title_full Scalable Load Balance / High Availability Architecture for Network Security Switch
title_fullStr Scalable Load Balance / High Availability Architecture for Network Security Switch
title_full_unstemmed Scalable Load Balance / High Availability Architecture for Network Security Switch
title_sort scalable load balance / high availability architecture for network security switch
publishDate 2005
url http://ndltd.ncl.edu.tw/handle/27747861150508532801
work_keys_str_mv AT yuanfanghuang scalableloadbalancehighavailabilityarchitecturefornetworksecurityswitch
AT huángyuǎnfāng scalableloadbalancehighavailabilityarchitecturefornetworksecurityswitch
AT yuanfanghuang jùyánzhǎnxìngqiěyǒugāokěyòngdùhéfùzàipínghéngjīzhìdewǎnglùānquánjiāohuànjījiàgòu
AT huángyuǎnfāng jùyánzhǎnxìngqiěyǒugāokěyòngdùhéfùzàipínghéngjīzhìdewǎnglùānquánjiāohuànjījiàgòu
_version_ 1718296912628547584