TY - GEN
T1 - A survey on firewall's early packet rejection techniques
AU - Zeidan, Safaa
AU - Trabelsi, Zouheir
PY - 2011
Y1 - 2011
N2 - Packet filtering plays a critical role in the performance of many network devices such as firewalls, routers and intrusion detection and prevention systems. Tremendous amount of research works on packet classification was proposed to optimize packet filtering. However, most works use deterministic techniques and do not take into consideration the traffic characteristics. Moreover, most packet classifiers give no specific consideration for optimizing early packet rejection (compared with packet acceptance), which is very important for improving firewall performance. In this paper, we are limited to survey firewall early packet rejection techniques. The strengths and limitations of the techniques are discussed. Also, some improvements have been proposed. This work can be the basis to enhance these techniques or for proposing new approaches that provide better firewall performance.
AB - Packet filtering plays a critical role in the performance of many network devices such as firewalls, routers and intrusion detection and prevention systems. Tremendous amount of research works on packet classification was proposed to optimize packet filtering. However, most works use deterministic techniques and do not take into consideration the traffic characteristics. Moreover, most packet classifiers give no specific consideration for optimizing early packet rejection (compared with packet acceptance), which is very important for improving firewall performance. In this paper, we are limited to survey firewall early packet rejection techniques. The strengths and limitations of the techniques are discussed. Also, some improvements have been proposed. This work can be the basis to enhance these techniques or for proposing new approaches that provide better firewall performance.
KW - Binary Decision Diagram
KW - Binary Search on Prefix Length
KW - Boolean Expression
KW - Early Rejection
KW - Hash Table
KW - Packet Classification
KW - Set cover
KW - Splay Tree
UR - http://www.scopus.com/inward/record.url?scp=79960018102&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=79960018102&partnerID=8YFLogxK
U2 - 10.1109/INNOVATIONS.2011.5893818
DO - 10.1109/INNOVATIONS.2011.5893818
M3 - Conference contribution
AN - SCOPUS:79960018102
SN - 9781457703140
T3 - 2011 International Conference on Innovations in Information Technology, IIT 2011
SP - 203
EP - 208
BT - 2011 International Conference on Innovations in Information Technology, IIT 2011
T2 - 2011 International Conference on Innovations in Information Technology, IIT 2011
Y2 - 25 April 2011 through 27 April 2011
ER -