DocumentCode :
1666061
Title :
Trie-based policy representations for network firewalls
Author :
Fulp, Errin W. ; Tarsa, Stephen J.
Author_Institution :
Dept. of Comput. Sci., Wake Forest Univ., Winston-Salem, NC, USA
fYear :
2005
Firstpage :
434
Lastpage :
441
Abstract :
Network firewalls remain the forefront defense for most computer systems. These critical devices filter traffic by comparing arriving packets to a list of rules, or security policy, in a sequential manner. Unfortunately packet filtering in this fashion can result in significant traffic delays, which is problematic for applications that require strict quality of service (QoS) guarantees. Given this demanding environment, new methods are needed to increase network firewall performance. This paper introduces a new technique for representing a security policy that maintains policy integrity and provides more efficient processing. The policy is represented as an n-ary retrieval tree, also referred to as a trie. The worst case processing requirement for the policy trie is a fraction compared a list representation, which only considers rules individually (1/5 the processing for TCP/IP networks). Furthermore unlike other representations, the n-ary trie developed in this paper can be proven to maintain policy integrity. The creation of policy trie structures is discussed in detail and their performance benefits are described theoretically and validated empirically.
Keywords :
authorisation; computer networks; quality of service; telecommunication security; QoS; TCP-IP networks; computer systems; network firewalls; packet filtering; quality of service; retrieval tree; traffic delays; trie-based policy representations; Application software; Computer networks; Computer science; Delay; Filtering; Filters; Hardware; Quality of service; TCPIP; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computers and Communications, 2005. ISCC 2005. Proceedings. 10th IEEE Symposium on
ISSN :
1530-1346
Print_ISBN :
0-7695-2373-0
Type :
conf
DOI :
10.1109/ISCC.2005.149
Filename :
1493763
Link To Document :
بازگشت