On optimal firewall rule ordering

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

7 Scopus citations

Abstract

In today's online connected world, almost all corporate networks use some form of perimeter firewalls to manage Internet connections and enforce a security policy at the corporate gateway. Although it can considerably enhance network security and protect business-critical information, a firewall with thousands of rules can become a bottleneck for network performance. The primary goal of this paper is to present a new rule order optimizer based on simulated annealing to find optimal configurations that minimize the average number of rule comparisons while preserving precedence relationships among disjoint rules. The proposed approach is evaluated and its effectiveness is compared with another approximate solution under several firewall configurations and policy profiles.

Original languageEnglish
Title of host publication2007 IEEE/ACS International Conference on Computer Systems and Applications, AICCSA 2007
Pages819-824
Number of pages6
DOIs
StatePublished - 2007

Publication series

Name2007 IEEE/ACS International Conference on Computer Systems and Applications, AICCSA 2007

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Computer Science Applications
  • Hardware and Architecture
  • Signal Processing

Fingerprint

Dive into the research topics of 'On optimal firewall rule ordering'. Together they form a unique fingerprint.

Cite this