A traffic-aware top-N firewall ruleset approximation algorithm

  • Authors:
  • Ho-Yu Lam;Donghan (Jarod) Wang;H. Jonathan Chao

  • Affiliations:
  • Polytechnic Institute of New York University, Brooklyn, NY;Polytechnic Institute of New York University, Brooklyn, NY;Polytechnic Institute of New York University, Brooklyn, NY

  • Venue:
  • Proceedings of the 6th ACM/IEEE Symposium on Architectures for Networking and Communications Systems
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

Packet classification is widely used in various network security and operation applications. Two of the main challenges are the increasing number of classification rules, amount of traffic and network line speed. In this poster, we investigate an approximation algorithm for selecting the top-N most frequently matched subset of rules from the original ruleset. Through simulations, we show that our approaches the optimal while runs in seconds, allowing online adaptation to changing traffic patterns.