A heuristic approach for firewall policy optimization

El Sayed M. El-Alfy*

*Corresponding author for this work

Research output: Contribution to journalConference articlepeer-review

8 Scopus citations

Abstract

A primary goal of this paper is to develop a heuristic approach based on genetic algorithms to enhance the firewall performance. Typical firewall policies may have thousands of rules and determining an optimal rule order that minimizes the average number of rule comparisons while maintaining the policy integrity is proven to be NP-hard. This problem is formulated as a binary integer program for which an optimal solution is obtained using the branch-and-bound technique. Then an alternative solution approach is devised based on genetic algorithms. Several experiments are conducted to evaluate the effectiveness of the proposed approach as compared to other rule-ordering techniques. Empirical results show the potential and flexibility of the proposed approach.

Original languageEnglish
Article number4195518
Pages (from-to)1782-1787
Number of pages6
JournalInternational Conference on Advanced Communication Technology, ICACT
Volume3
DOIs
StatePublished - 2007

Keywords

  • Access control
  • Firewalls
  • Genetic algorithms
  • Network security

ASJC Scopus subject areas

  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'A heuristic approach for firewall policy optimization'. Together they form a unique fingerprint.

Cite this