Level Stateful Filtering 対応OS 軽量さ (⇄複雑さ) nwfilter (KVM) Packet ◦ (conntrack) Linux ◦ SDN (Open vSwitch, VMWare NSX) Packet ◦ All △ VMI (VMwall1, xFilter2, AL-Safe3) Packet & Process ◦(?) Linux △ AWS Security Group Packet △ All ◦ BPF in BitVisor Packet △* (eBPF Mapを使う⽅法は考えられる) All ◎ [1] A. Srivastava and J. Giffin. Tamper-resistant, application-aware blocking of malicious network connections. In RAID, pages 39‒58. Springer, 2008. [2] K. Kourai, T. Azumi, and S. Chiba. Efficient and fine-grained vmm-level packet filtering for self-protection. IJARAS, 5(2):83‒100, Apr. 2014. [3] A. Giannakou, L. Rilling, J.-L. Pazat, and C. Morin. AL-SAFE: A secure self-adaptable application-level firewall for IaaS clouds. In CloudCom, pages 383‒390. IEEE, 2016. * TCPのACKフィールドを⾒るなどで⾃分から開始したコネクションを簡易的に判断することは可能