• DocumentCode
    3608095
  • Title

    Modelling and analysis of rule-based network security middleboxes

  • Author

    Salah, Khaled ; Chaudary, Aslam

  • Author_Institution
    Electr. & Comput. Eng. Dept., Khalifa Univ. of Sci., Sharjah, United Arab Emirates
  • Volume
    9
  • Issue
    6
  • fYear
    2015
  • Firstpage
    305
  • Lastpage
    312
  • Abstract
    This study presents an analytical model for rule-based network security middleboxes as those of network firewalls, intrusion detection systems and email spam filters. In these systems, incoming packets carrying requests arrive at the middlebox and obtain queued for processing in multiple stages. The stages consist of first a main stage for packet processing and then subsequent stages of rulebase interrogation in which rules or conditions are checked sequentially until a match is triggered. The service at these stages is characterised to be mutually exclusive; that is, only one stage is active at any time. The authors derive useful formulas that can predict the middlebox performance, taking into account its incoming request rate, the queue size and the processing capacity of the middlebox, and thereby proper engineering capacity of the middlebox can be achieved.
  • Keywords
    computer network security; knowledge based systems; queueing theory; email spam filters; intrusion detection systems; middlebox performance; middlebox processing capacity; network firewalls; packet processing; queue size; rule-base interrogation; rule-based network security middleboxes;
  • fLanguage
    English
  • Journal_Title
    Information Security, IET
  • Publisher
    iet
  • ISSN
    1751-8709
  • Type

    jour

  • DOI
    10.1049/iet-ifs.2014.0545
  • Filename
    7295684