Firewall performance optimization using data mining techniques

Umniya Mustafa, Mohammad M. Masud, Zouheir Trabelsi, Timothy Wood, Zainab Al Harthi

Research output: Chapter in Book/Report/Conference proceedingConference contribution

11 Citations (Scopus)

Abstract

This paper presents a novel approach to improve firewall performance using data mining techniques. A traditional packet filtering firewall compares a packet against each filtering rule until a match is found. The filtering rules are stored as a rule list. Therefore, the time required to process a packet depends linearly on the number of filtering rules. This time can be prohibitively large for a firewall containing hundreds of rules and the firewall can be a bottleneck for the network if high bandwidth is required. To enhance the firewall performance, we propose a data mining solution. In this approach, instead of comparing the packet with each of the filtering rules, the firewall predicts which rule is most likely going to match the packet. This significantly reduces the processing time taken by the firewall to filter each packet and thus improves its performance. Comparisons were made between the cumulative processing time taken by a standard firewall and the enhanced firewall with data mining to process millions of packets. Compared to the standard firewall, the enhanced firewall took 40% less time in processing the packets.

Original languageEnglish
Title of host publication2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013
Pages934-940
Number of pages7
DOIs
Publication statusPublished - 2013
Event2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013 - Cagliari, Sardinia, Italy
Duration: Jul 1 2013Jul 5 2013

Publication series

Name2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013

Other

Other2013 9th International Wireless Communications and Mobile Computing Conference, IWCMC 2013
Country/TerritoryItaly
CityCagliari, Sardinia
Period7/1/137/5/13

Keywords

  • Data mining
  • Decision-tree
  • Firewall
  • Packet filtering
  • Performance optimization

ASJC Scopus subject areas

  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Firewall performance optimization using data mining techniques'. Together they form a unique fingerprint.

Cite this