ScienceDirect® Home Skip Main Navigation Links
You have guest access to ScienceDirect. Find out more.
 
Home
Browse
My Settings
Alerts
Help
 Quick Search
 Search tips (Opens new window)
    Clear all fields    
Computer Communications
Volume 30, Issue 7, 26 May 2007, Pages 1487-1497
Wired/Wireless Internet Communications
 
Font Size: Decrease Font Size  Increase Font Size
 Abstract - selected
Article
Purchase PDF (539 K)

Article Toolbox
  E-mail Article   
  Add to my Quick Links   
Bookmark and share in 2collab (opens in new window)
Request permission to reuse this article
  Cited By in Scopus (0)
 
 
 
Related Articles in ScienceDirect
View More Related Articles
 
View Record in Scopus
 
doi:10.1016/j.comcom.2007.01.019    
How to Cite or Link Using DOI (Opens New Window)

Copyright © 2007 Elsevier B.V. All rights reserved.

Crosslayer firewall interaction as a means to provide effective and efficient protection at mobile devices

Purchase the full-text article



References and further reading may be available for this article. To view references and further reading you must purchase this article.

Peter Langendoerfera, Corresponding Author Contact Information, E-mail The Corresponding Author, Krzysztof Piotrowskia, Steffen Petera and Martin Lehmannb

aIHP, Im Technologiepark 25, 15236 Frankfurt (Oder), Germany

bDFS Deutsche Flugsicherung GmbH, Langen, SH/IR, Am DFS-Campus 2, 63225 Langen, Germany


Available online 16 February 2007.

Abstract

In this paper, we discuss packet filtering firewalls and an application level gateway approach used to secure handheld devices. We propose a firewall management plane as a means for crosslayer interaction. In our approach the application level gateway updates the firewall rules based on its knowledge about whether or not a certain source is sending malicious packets. Hereby, we pursue a policy of removing malicious packets as close as possible to the network interface. We show that in case of secure web service such a crosslayer interaction can significantly decrease the CPU load in case of attacks, i.e., if many malicious packets arrive at the handheld device. Our measurement results show that our crosslayer approach can reduce the CPU load caused by the application layer gateway by about 10–30%. Finally, we propose an integrated firewall processing approach that promises further improvements. It integrates the application controlled firewall before the MAC and provides crosslayer mechanisms to reduce the performance issues of traditional firewall approaches.

Keywords: Firewall management plane; Crosslayer interaction; XML; MAC firewall; Mobile devices

Article Outline

1. Introduction
2. Related work
3. Crosslayer interaction to reduce firewall effort
3.1. Basic idea
3.2. Implementation
4. Measurements
4.1. IP layer packet filtering
4.2. Web service gateway
4.3. Crosslayer interaction
5. Extending crosslayer interaction to lower layers
5.1. Crosslayer communication
5.2. Integrated layer firewall processing
6. Conclusions and outlook
Acknowledgements
References
Vitae












Corresponding Author Contact InformationCorresponding author. Tel.: +49 335 56 25 350; fax: +49 335 56 25 671.

Computer Communications
Volume 30, Issue 7, 26 May 2007, Pages 1487-1497
Wired/Wireless Internet Communications
 
Home
Browse
My Settings
Alerts
Help
Elsevier.com (Opens new window)
About ScienceDirect  |  Contact Us  |  Information for Advertisers  |  Terms & Conditions  |  Privacy Policy
Copyright © 2008 Elsevier B.V. All rights reserved. ScienceDirect® is a registered trademark of Elsevier B.V.