Firewalls White Papers
Efficient Embedded Firewall for Communication Appliances
Overview Denial-of-Service attacks are a major concern in VoIP deployments. IP phones are especially vulnerable because of their inherent imbalance in network capacity and processing power. In other words, a packet flood can easily bring an IP Phone down long before the network saturation point is reached. This paper presents the ideas behind the design of an efficient firewall to protect against DoS attacks. The main contribution lies in the novelty of packet classification heuristics by leveraging the behavior specific to VoIP. These include state based rule-partitioning and flow-rate based rule update. The ideas and the evident contrast to generic firewalls should also facilitate firewall design for other applications.
| Publisher | Avaya | File Format | |
|---|---|---|---|
| Date Published | April 2005 | ||
| Format | White Papers | ||
| Topics | |||


