DocumentCode
2811197
Title
Enabling flexible packet filtering through the K-map priority elimination technique
Author
Ben Neji, Nizar ; Bouhoula, Adel ; Kimura, Masato
Author_Institution
Higher Sch. of Commun. of Tunis (SupCom), Univ. of Carthage, Tunis, Tunisia
fYear
2011
fDate
4-7 Oct. 2011
Firstpage
1
Lastpage
8
Abstract
The process of packet filtering becomes time consuming as filtering policies become larger and more complex. New firewall designs are needed to meet the challenges associated with the high-speed networks. For this reason, access control lists in firewalls need to be flexible enough to give us the possibility to implement efficiently new high-performance filtering strategies. The precedence relationships within the access control rules are considered as being one of the most important handicap remaining unsolved in the context of optimization. In this paper, we introduce a Karnaugh map (k-map) based technique able to remove totally the dependencies between rules without changing the filtering behavior (i.e. input and output lists of rules remain semantically equivalent). On one hand, statistical rule ordering models become easy to implement, provide a differentiated quality of service and enable to reach a good processing time. On the other hand, dependency removal is very useful in the context parallelization especially when the access policy has to be equitably distributed among multiple firewalls. We have implemented this new technique and the first computer experiments were very promising.
Keywords
access control; authorisation; computer network security; K-map priority elimination technique; Karnaugh map based technique; access control; dependency removal; firewall designs; flexible packet filtering; statistical rule ordering models; Complexity theory; Context; Educational institutions; IP networks; Optimization; Redundancy; Security; Firewall; packet filtering; parallelization; priority elimination; security policy; statistical model;
fLanguage
English
Publisher
ieee
Conference_Titel
Local Computer Networks (LCN), 2011 IEEE 36th Conference on
Conference_Location
Bonn
ISSN
0742-1303
Print_ISBN
978-1-61284-926-3
Type
conf
DOI
10.1109/LCN.2011.6115188
Filename
6115188
Link To Document