• DocumentCode
    2255008
  • Title

    Algorithms for improving the dependability of firewall and filter rule lists

  • Author

    Hazelhurst, Scott ; Attar, Adi ; Sinnappan, Raymond

  • Author_Institution
    Dept. of Comput. Sci., Univ. of the Witwatersrand, Johannesburg, South Africa
  • fYear
    2000
  • fDate
    2000
  • Firstpage
    576
  • Lastpage
    585
  • Abstract
    Network firewalls and routers use a rule database to decide which packets will be allowed from one network on to another. By filtering packets, the firewalls and routers can improve security and performance. However, as the size of the rule list increases, it becomes difficult to maintain and validate the rules, and lookup latency may increase significantly. Both these factors tend to limit the ability of firewall systems to protect networks. This paper presents a new technique for representing rule databases. This representation (based on ordered binary decision diagrams) can be used in two ways: faster lookup algorithms can allow larger rule sets to be used without sacrificing performance; and algorithms for validating rule sets and changes to rule sets can be used. The overall dependability of the system is improved by allowing larger and more sophisticated rules sets, and by having greater confidence in the rule sets´ correctness
  • Keywords
    authorisation; binary decision diagrams; filters; packet switching; reliability; table lookup; telecommunication computing; telecommunication network routing; telecommunication security; dependability; filter rule lists; firewall rule lists; lookup algorithms; lookup latency; network firewalls; network protection; network routers; ordered binary decision diagrams; packet filtering; packet switching; performance; rule database representation; rule maintenance; rule set changes; rule validation; rules set size; security; Africa; Computer science; Data security; Databases; Delay; Filtering; Finite impulse response filter; Protection; TCPIP; Telecommunication traffic;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks, 2000. DSN 2000. Proceedings International Conference on
  • Conference_Location
    New York, NY
  • Print_ISBN
    0-7695-0707-7
  • Type

    conf

  • DOI
    10.1109/ICDSN.2000.857593
  • Filename
    857593