Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Towards a Deep-Packet-Filter Toolkit for Securing Legacy Resources

Users of a network system often require access to legacy resources. Providing this access is a difficult task for system administrators because the access protocols for those resources are typically insecure. A common approach is to develop a custom wrapper or proxy that securely processes user requests before forwarding them to the legacy server. The problem with this approach is that administrators must develop a custom solution for every resource. We believe that there are common requirements for managing these resources that can be addressed from a more centralized model. The userspace queuing extensions of the Netfilter firewall modules provide a generic environment in which protocol-aware deep packet filters can be constructed to enhance the security of resource access protocols. We employ this environment to strengthen two commonly used legacy protocols, and compare their requirements. We show that it is possible to secure legacy resources with minimal degradation in performance. We also discuss considerations for development of a deep packet filter toolkit to aid system administrators in securely managing legacy network resources.

James Deverick, The College of William and Mary

BibTeX
@inproceedings {269112,
author = {James Deverick},
title = {Towards a {Deep-Packet-Filter} Toolkit for Securing Legacy Resources},
booktitle = {19th Large Installation System Administration Conference (LISA 05)},
year = {2005},
address = {San Diego, CA},
url = {https://www.usenix.org/conference/lisa-05/towards-deep-packet-filter-toolkit-securing-legacy-resources},
publisher = {USENIX Association},
month = dec
}
Download

Links

Paper: 
http://usenix.org/event/lisa05/tech/full_papers/deverick/deverick.pdf
Paper (HTML): 
http://usenix.org/event/lisa05/tech/full_papers/deverick/deverick_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

LISA is a registered trademark of the USENIX Association.

  • Privacy Policy
  • Contact Us