Packet flow histograms to improve firewall efficiency

Zouheir Trabelsi, Liren Zhang, Safaa Zeidan

Research output: Chapter in Book/Report/Conference proceedingConference contribution

9 Citations (Scopus)

Abstract

This paper presents a novel mechanism based on the histograms of packet filtering, which are able to effectively monitor firewall performance in real-time and to predict the patterns of packet filtering in terms of rules order and rule-fields order. Furthermore, the mechanism becomes even more significant when firewall is heavily loaded with burst traffic. A comparison of the proposed approach and the other conventional approaches, including static rule order approach and dynamic rule order approach is presented.

Original languageEnglish
Title of host publicationICICS 2011 - 8th International Conference on Information, Communications and Signal Processing
DOIs
Publication statusPublished - 2011
Event8th International Conference on Information, Communications and Signal Processing, ICICS 2011 - Singapore, Singapore
Duration: Dec 13 2011Dec 16 2011

Publication series

NameICICS 2011 - 8th International Conference on Information, Communications and Signal Processing

Other

Other8th International Conference on Information, Communications and Signal Processing, ICICS 2011
Country/TerritorySingapore
CitySingapore
Period12/13/1112/16/11

Keywords

  • firewall early rejection
  • optimization of rule-fields ordering
  • optimization of rules ordering
  • packet flow matching histogram

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Information Systems
  • Signal Processing

Cite this