Compiling Policy Descriptions into Reconfigurable Firewall Processors

  • Authors:
  • T. K. Lee;S. Yusuf;W. Luk;M. Sloman;E. Lupu;N. Dulay

  • Affiliations:
  • -;-;-;-;-;-

  • Venue:
  • FCCM '03 Proceedings of the 11th Annual IEEE Symposium on Field-Programmable Custom Computing Machines
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

We describe a framework for capturing firewall requirementsas high-level descriptions based on the policy specificationlanguage Ponder. The framework provides abstractionfrom hardware implementation while allowingperformance control through constraints. Our hardwarecompilation strategy for such descriptions involves a rulereduction step to produce a hardware firewall rule representation.Three main methods have also been developedfor resource optimisation: partitioning, elimination, andsharing. A case study involving five sets of filter rulesindicates that it is possible to reduce 67-80% of hardwareresources over techniques based on regular content-addressablememory, and 24-63% over methods based onirregular content-addressable memory.