• DocumentCode
    2374309
  • Title

    Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvement

  • Author

    Trabelsi, Zouheir ; Zeidan, Safaa

  • Author_Institution
    Fac. of Inf. Technol., UAE Univ., Al-Ain, United Arab Emirates
  • fYear
    2012
  • fDate
    10-15 June 2012
  • Firstpage
    1074
  • Lastpage
    1078
  • Abstract
    This paper presents a mechanism to improve firewall packet filtering time through optimizing the order of security policy filtering fields for early packet rejection. The proposed mechanism is based on the optimization of the filtering fields order according to traffic statistics. Furthermore, the mechanism uses multilevel packet filtering, and in each level unwanted packets are rejected as early as possible. So, the proposed mechanism can be considered also as a device protection mechanism against denial of service (DoS) attacks targeting the default policy rule. In addition, early packet acceptance is done through using the splay tree data structure which changes dynamically according to traffic flows. So, repeated packets will have less memory accesses and therefore reducing the overall packets matching time. The proposed technique aims to overcome some of the performance limitations of the previous technique, named Self Adjusting Binary Search on Prefix Length (SA-BSPL). The numerical results obtained by simulations demonstrate that the proposed mechanism is able to significantly improve the firewall performance in terms of cumulative packet processing time compared to SA-BSPL technique.
  • Keywords
    authorisation; computer network security; filtering theory; statistical analysis; telecommunication traffic; tree data structures; DoS attacks; SA-BSPL technique; cumulative packet processing time; default policy rule; denial of service attacks; device protection mechanism; early packet acceptance; early packet rejection; filtering field order optimization; firewall packet filtering time; firewall performance improvement; level unwanted packet rejection; multilevel early packet filtering technique; packet matching time; security policy filtering fields; self-adjusting binary search on prefix length; splay tree data structure; traffic statistics; Computer crime; Computers; Filtering; Mathematical model; Optimization; Tree data structures; Binary Search on Prefix Length; Early packet Rejection; Hash Table; Packet Classification; Splay Tree;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications (ICC), 2012 IEEE International Conference on
  • Conference_Location
    Ottawa, ON
  • ISSN
    1550-3607
  • Print_ISBN
    978-1-4577-2052-9
  • Electronic_ISBN
    1550-3607
  • Type

    conf

  • DOI
    10.1109/ICC.2012.6364218
  • Filename
    6364218