• DocumentCode
    2811197
  • Title

    Enabling flexible packet filtering through the K-map priority elimination technique

  • Author

    Ben Neji, Nizar ; Bouhoula, Adel ; Kimura, Masato

  • Author_Institution
    Higher Sch. of Commun. of Tunis (SupCom), Univ. of Carthage, Tunis, Tunisia
  • fYear
    2011
  • fDate
    4-7 Oct. 2011
  • Firstpage
    1
  • Lastpage
    8
  • Abstract
    The process of packet filtering becomes time consuming as filtering policies become larger and more complex. New firewall designs are needed to meet the challenges associated with the high-speed networks. For this reason, access control lists in firewalls need to be flexible enough to give us the possibility to implement efficiently new high-performance filtering strategies. The precedence relationships within the access control rules are considered as being one of the most important handicap remaining unsolved in the context of optimization. In this paper, we introduce a Karnaugh map (k-map) based technique able to remove totally the dependencies between rules without changing the filtering behavior (i.e. input and output lists of rules remain semantically equivalent). On one hand, statistical rule ordering models become easy to implement, provide a differentiated quality of service and enable to reach a good processing time. On the other hand, dependency removal is very useful in the context parallelization especially when the access policy has to be equitably distributed among multiple firewalls. We have implemented this new technique and the first computer experiments were very promising.
  • Keywords
    access control; authorisation; computer network security; K-map priority elimination technique; Karnaugh map based technique; access control; dependency removal; firewall designs; flexible packet filtering; statistical rule ordering models; Complexity theory; Context; Educational institutions; IP networks; Optimization; Redundancy; Security; Firewall; packet filtering; parallelization; priority elimination; security policy; statistical model;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks (LCN), 2011 IEEE 36th Conference on
  • Conference_Location
    Bonn
  • ISSN
    0742-1303
  • Print_ISBN
    978-1-61284-926-3
  • Type

    conf

  • DOI
    10.1109/LCN.2011.6115188
  • Filename
    6115188