Lightweight bare-metal stateful firewall

Publikation: Beitrag in Buch/Konferenzbericht/Sammelband/GutachtenBeitrag in KonferenzbandBeigetragenBegutachtung

Beitragende

  • Yihuan Xing - , National University of Singapore (Autor:in)
  • Ford Long Wong - , DSO National Laboratory, Singapore (Autor:in)
  • Akash Kumar - , National University of Singapore (Autor:in)

Abstract

A firewall is a crucial security element in modern computer networks. This work investigates and demonstrates the implementation of a lightweight TCP/IP firewall in a bare-metal environment, on a commercial embedded ARM device. Compared to an implementation having an operating system (OS), using bare-metal design enables reduction of exposure to potential vulnerabilities in OS code, and provides a more dependable system. The implemented firewall provides both static and stateful filtering capabilities, and is configurable in a user-friendly way. As the architecture of the commercial hardware used was not available under closed source licensing, it was discovered through analysis at both hardware and software levels. Some challenges were encountered, and tools were developed to address these. The prototype is validated through functional testing in a controlled environment successfully.

Details

OriginalspracheEnglisch
Titel2014 IEEE 20th Pacific Rim International Symposium on Dependable Computing
Seiten53-58
Seitenumfang6
ISBN (elektronisch)978-1-4799-6474-1
PublikationsstatusVeröffentlicht - 3 Dez. 2014
Peer-Review-StatusJa
Extern publiziertJa

Publikationsreihe

ReihePacific Rim International Symposium on Dependable Computing
ISSN1541-0110

Konferenz

Titel20th IEEE Pacific Rim International Symposium on Dependable Computing, PRDC 2014
Dauer19 - 21 November 2014
StadtSingapore
LandSingapur

Schlagworte

Forschungsprofillinien der TU Dresden

Schlagwörter

  • ARM, bare-metal, encryptor, firewall, stateful