File Download

There are no files associated with this item.

  Links for fulltext
     (May Require Subscription)
Supplementary

Article: A general framework for benchmarking firewall optimization techniques

TitleA general framework for benchmarking firewall optimization techniques
Authors
KeywordsACL optimization
ACL partitioning
Data mining
Fires
Firewall management
Firewall optimization
Inspection
Internet
Optimization
Partitioning algorithms
Servers
Issue Date2008
Citation
IEEE Transactions on Network and Service Management, 2008, v. 5, n. 4, p. 227-238 How to Cite?
AbstractFirewalls are among the most pervasive network security mechanisms, deployed extensively from the borders of networks to end systems. The complexity of modern firewall policies has raised the computational requirements for firewall implementations, potentially limiting the throughput of networks. Administrators currently rely on ad hoc solutions to firewall optimization. To address this problem, a few automatic firewall optimization techniques have been proposed, but there has been no general approach to evaluate the optimality of these techniques. In this paper we present a general framework for rule-based firewall optimization. We give a precise formulation of firewall optimization as an integer programming problem and show that our framework produces optimal reordered rule sets that are semantically equivalent to the original rule set. Our framework considers the complex interactions among the rules in firewall configurations and relies on a novel partitioning of the packet space defined by the rules themselves. For validation, we employ this framework on real firewall rule sets for a quantitative evaluation of existing heuristic approaches. Our results indicate that the framework is general and faithfully captures performance benefits of firewall optimization heuristics. © 2009 IEEE.
Persistent Identifierhttp://hdl.handle.net/10722/346546
ISSN
2023 Impact Factor: 4.7
2023 SCImago Journal Rankings: 1.762

 

DC FieldValueLanguage
dc.contributor.authorMisherghi, Ghassan-
dc.contributor.authorYuan, Lihua-
dc.contributor.authorSu, Zhendong-
dc.contributor.authorChuah, Chen Nee-
dc.contributor.authorChen, Hao-
dc.date.accessioned2024-09-17T04:11:39Z-
dc.date.available2024-09-17T04:11:39Z-
dc.date.issued2008-
dc.identifier.citationIEEE Transactions on Network and Service Management, 2008, v. 5, n. 4, p. 227-238-
dc.identifier.issn1932-4537-
dc.identifier.urihttp://hdl.handle.net/10722/346546-
dc.description.abstractFirewalls are among the most pervasive network security mechanisms, deployed extensively from the borders of networks to end systems. The complexity of modern firewall policies has raised the computational requirements for firewall implementations, potentially limiting the throughput of networks. Administrators currently rely on ad hoc solutions to firewall optimization. To address this problem, a few automatic firewall optimization techniques have been proposed, but there has been no general approach to evaluate the optimality of these techniques. In this paper we present a general framework for rule-based firewall optimization. We give a precise formulation of firewall optimization as an integer programming problem and show that our framework produces optimal reordered rule sets that are semantically equivalent to the original rule set. Our framework considers the complex interactions among the rules in firewall configurations and relies on a novel partitioning of the packet space defined by the rules themselves. For validation, we employ this framework on real firewall rule sets for a quantitative evaluation of existing heuristic approaches. Our results indicate that the framework is general and faithfully captures performance benefits of firewall optimization heuristics. © 2009 IEEE.-
dc.languageeng-
dc.relation.ispartofIEEE Transactions on Network and Service Management-
dc.subjectACL optimization-
dc.subjectACL partitioning-
dc.subjectData mining-
dc.subjectFires-
dc.subjectFirewall management-
dc.subjectFirewall optimization-
dc.subjectInspection-
dc.subjectInternet-
dc.subjectOptimization-
dc.subjectPartitioning algorithms-
dc.subjectServers-
dc.titleA general framework for benchmarking firewall optimization techniques-
dc.typeArticle-
dc.description.naturelink_to_subscribed_fulltext-
dc.identifier.doi10.1109/TNSM.2009.041104-
dc.identifier.scopuseid_2-s2.0-67449085828-
dc.identifier.volume5-
dc.identifier.issue4-
dc.identifier.spage227-
dc.identifier.epage238-

Export via OAI-PMH Interface in XML Formats


OR


Export to Other Non-XML Formats