Logo image
The Design and Implementation of Layer 7 High Speed Security Switch
Thesis

The Design and Implementation of Layer 7 High Speed Security Switch

Chih-Hao Chen
Masters, 國立清華大學, 資訊工程學系
2003

Abstract

第二層交換機 網路安全交換機 入侵偵測 入侵偵測防禦 防火牆 蠕蟲 網路攻擊
The network security issues will be paid more and more attentions in the coming years as the deployment of new and treating Internet applications, such as P2P (peer-to-peer), IM (Instant Messenger), and Spyware/Adware are achieved in a rapid way. Also the DOS/DDOS attacking, such as worms (NetKey, Sasser, MS-Blaster, SQL Slammer, CodeRed, etc), will be launched more frequently as the attacking tools are more and more friendly to use. It has been pointed out that the pure software-based solution for clients to prevent these treating applications and the attacking worms is not feasible any more. Although the Intrusion Detection and Prevention System (IDP/IPS) is becoming more popular to prevent such emerging treats and attacks, it is typically installed between the router and firewall of an enterprise. Thus, for the treating/attacking traffic within the intranet, the single IDP/IPS system is unable to furnish a complete or efficient protection due to the lack of defense-in-depth mechanism. As L2 switches are the most widely deployed network equipments in the world, it seems that the most efficient way to protect the intranet from the attacking of affected clients is to upgrade the L2 switches into security switches, where the traffic between each switching port is verified and protected. In this thesis, we propose a flexible architecture for network security switch so that the traffic between switching ports is inspected and protected in a cost effective way. In this architecture, a gigabit security engine with layer-7 packet inspection capability is designed to accompany with traditional managed L2 switches. By employing the VLAN technology intelligently, every packet coming from each of the switching port is forwarded to the security engine via the gigabit interface, and after the packet is inspected by the security engine, it is either been dropped (abnormal packet) or sent back (normal packet) to the switch and forwarded to the output port by the L2 switch according to the original destination MAC address of the packet. The proposed security switch architecture not only provides a deep inspection protection for the intranet traffic but also furnishes a very cost effective solution as the installed L2 switched are upgraded instead of been replaced.

Metrics

1 Record Views

Details

Logo image