DocumentCode
775845
Title
On Dynamic Optimization of Packet Matching in High-Speed Firewalls
Author
Hamed, Hazem ; El-Atawy, Adel ; Al-Shaer, Ehab
Author_Institution
Sch. of Comput. Sci., DePaul Univ.
Volume
24
Issue
10
fYear
2006
Firstpage
1817
Lastpage
1830
Abstract
Packet matching plays a critical role in the performance of many network devices and a tremendous amount of research has already been invested to come up with better optimized packet filters. However, most of the related works use deterministic techniques and do not exploit the traffic characteristics in their optimization schemes. In addition, most packet classifiers give no specific consideration for optimizing packet rejection, which is important for many filtering devices like firewalls. Our contribution in this paper is twofold. First, we present a novel algorithm for maximizing early rejection of unwanted flows with minimal impact on other flows. Second, we present a new packet filtering dynamic optimization technique that uses statistical search trees to utilize traffic characteristics and minimize the average packet matching time. The proposed techniques timely adapt to changes in the traffic conditions by performing simple calculations for optimizing the search data structure. Our techniques are practically attractive because they exhibit simple-to-implement and easy-to-deploy algorithms. Our extensive evaluation study using Internet traces shows that the proposed techniques can significantly minimize the packet filtering time with reasonable memory space requirements
Keywords
Internet; dynamic programming; filtering theory; telecommunication traffic; tree data structures; tree searching; Internet; data structure; dynamic optimization; high-speed firewall; packet filtering; packet matching; statistical search tree; traffic characteristics; Data structures; Diffserv networks; Information filtering; Information filters; Internet; Intrusion detection; Matched filters; Protocols; Quality of service; Telecommunication traffic;
fLanguage
English
Journal_Title
Selected Areas in Communications, IEEE Journal on
Publisher
ieee
ISSN
0733-8716
Type
jour
DOI
10.1109/JSAC.2006.877140
Filename
1705614
Link To Document