Study of methods for endpoint aware inspection in a next generation firewall


연구 분야: Safety



학회: Cybersecurity


초록

Given the global increase in remote work with the COVID-19 pandemic and deperimeterization due to cloud deployment of next generation firewalls, the concept of a next generation firewall is at a breaking point. It is becoming more difficult to define the barrier between the good and the bad. To provide the best security for an endpoint with minimal false positives or false negatives it is often necessary to identify the communicating endpoint application. In this study, we present an analysis of key research and methods for providing endpoint aware protection in the context of a next generation firewall. We examine both academic research as well as state-of-the-art of the existing next generation firewall implementations. We divide endpoint application identification into passive and active methods. For passive endpoint application identification, we study several traffic fingerprinting methods for different protocols. For active methods we consider active scanning, endpoint metadata analysis and content injection and reference existing implementations. We conclude that there are several open areas for future research, and that none of the considered methods is a silver bullet solution for endpoint aware inspection in the context of a next generation firewall. To our best knowledge, this is the first study to examine current research and existing implementations of endpoint aware inspection.


Author Profile
Jenny Heino

Department of Computing University of Turku Turku Finland

Finland
Author Profile
Antti Hakkala

Forcepoint LLC Helsinki Finland

Finland
Author Profile
Seppo Virtanen

Department of Computing University of Turku Turku Finland

Finland

📄 논문 정보

발행 연도 2022년
인용수 0
출판 국가 Finland
사이트 Springer
좋아요 수 0

연관 논문 목록 (29건)