Firewall packet filtering optimization using statistical traffic awareness test

  • Authors:
  • Zouheir Trabelsi;Liren Zhang;Safaa Zeidan

  • Affiliations:
  • Faculty of Information Technology, UAE University, Al-Ain, UAE;Faculty of Information Technology, UAE University, Al-Ain, UAE;Faculty of Information Technology, UAE University, Al-Ain, UAE

  • Venue:
  • ICICS'12 Proceedings of the 14th international conference on Information and Communications Security
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we present a mechanism that utilizes network traffic behavior and packet filtering statistics to improve firewall performance. The proposed mechanism allows optimizing the filtering rules order and their corresponding fields order upon certain threshold qualification following the divergence of the traffic behavior. The current and previous traffic windows statistics are used to check the system stability using Chi-Square Test. The achieved gain in processing time compared to related mechanisms is due to minimizing the overhead corresponding to the frequency of updating the security policy rule/field structures.