Linear-tree rule structure for firewall optimization

  • Authors:
  • Liang Zhao;Akira Shimae;Hiroshi Nagamochi

  • Affiliations:
  • Kyoto University, Kyoto, Japan;Kyoto University, Kyoto, Japan;Kyoto University, Kyoto, Japan

  • Venue:
  • CIIT '07 The Sixth IASTED International Conference on Communications, Internet, and Information Technology
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Given a list of filtering rules with individual hitting probabilities, it is known that the average processing time of a linear-search based firewall can be minimized by searching rules in some appropriate order. This paper proposes a new yet simple technique called the linear-tree structure. It utilizes an advanced feature of modern firewalls, the "goto"-like statement, to transform the given rule list into a rule set that is functionally equivalent to the original but organized in a more efficient structure. We show it is possible to achieve much more improvement than previous, rule-reordering based studies. To demonstrate this, we study by both simulation experiment and test with real firewall.