loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
1997 IEEE Symposium on Security and Privacy
An MBone Proxy for an Application Gateway Firewall
Oakland, CA
May 04-May 07
ISBN: 0-8186-7828-3
Kelly Djahandari, Trusted Information Systems, Inc.
Daniel F. Sterne, Trusted Information Systems, Inc.
The Internet's multicast backbone (MBone) holds great potential for many organizations because it supports low-cost audio and video conferencing and carries live broadcasts of an increasing number of public interest events. MBone conferences are transmitted via unauthenticated multicast datagrams, which unfortunately convey significant security vulnerabilities to any system that receives them. For this reason, most application gateway firewalls block MBone datagrams sent from the Internet and prevent them from reaching hosts on internal networks.This paper describes the design and rationale for a new set of facilities for the TIS Internet Firewall Toolkit (FWTK). These facilities, which are fully implemented, significantly reduce the security risks of observing or participating in MBone conferences. They impose no functional constraints on MBone applications and are transparent to users. Configuration options that support tradeoffs among security, performance, and ease of use are discussed.
Citation:
Kelly Djahandari, Daniel F. Sterne, "An MBone Proxy for an Application Gateway Firewall," sp, pp.0072, 1997 IEEE Symposium on Security and Privacy, 1997
Usage of this product signifies your acceptance of the Terms of Use.