Firewall performance optimization using data mining techniques

Umniya Mustafa, Mohammad M. Masud, Zouheir Trabelsi, Timothy Wood, Zainab Al Harthi

    Research output: Chapter in Book/Report/Conference proceedingConference contribution

    9 Citations (Scopus)

    Abstract

    This paper presents a novel approach to improve firewall performance using data mining techniques. A traditional packet filtering firewall compares a packet against each filtering rule until a match is found. The filtering rules are stored as a rule list. Therefore, the time required to process a packet depends linearly on the number of filtering rules. This time can be prohibitively large for a firewall containing hundreds of rules and the firewall can be a bottleneck for the network if high bandwidth is required. To enhance the firewall performance, we propose a data mining solution. In this approach, instead of comparing the packet with each of the filtering rules, the firewall predicts which rule is most likely going to match the packet. This significantly reduces the processing time taken by the firewall to filter each packet and thus improves its performance. Comparisons were made between the cumulative processing time taken by a standard firewall and the enhanced firewall with data mining to process millions of packets. Compared to the standard firewall, the enhanced firewall took 40% less time in processing the packets.

    Original languageEnglish
    Title of host publication2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013
    Pages934-940
    Number of pages7
    DOIs
    Publication statusPublished - Sept 16 2013
    Event2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013 - Cagliari, Sardinia, Italy
    Duration: Jul 1 2013Jul 5 2013

    Publication series

    Name2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013

    Other

    Other2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013
    Country/TerritoryItaly
    CityCagliari, Sardinia
    Period7/1/137/5/13

    Keywords

    • Data mining
    • Decision-tree
    • Firewall
    • Packet filtering
    • Performance optimization

    ASJC Scopus subject areas

    • Computer Networks and Communications

    Fingerprint

    Dive into the research topics of 'Firewall performance optimization using data mining techniques'. Together they form a unique fingerprint.

    Cite this