ROFL: routing as the firewall layer

  • Authors:
  • Hang Zhao;Chi-Kin Chau;Steven M. Bellovin

  • Affiliations:
  • Columbia University, New York, NY, USA;University of Cambridge, Cambridge, UK;Columbia University, New York, NY, USA

  • Venue:
  • Proceedings of the 2008 workshop on New security paradigms
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

We propose a new firewall architecture that treats port numbers as part of the IP address. Hosts permit connectivity to a service by advertising the IPaddr:port/48 address; they block connectivity by ensuring that there is no route to it. This design, which is especially well-suited to MANETs, provides greater protection against insider attacks than do conventional firewalls, but drops unwanted traffic far earlier than distributed firewalls do.