• DocumentCode
    2932981
  • Title

    Splay trees based early packet rejection mechanism against DoS traffic targeting firewall default security rule

  • Author

    Trabelsi, Zouheir ; Zeidan, Safaa

  • Author_Institution
    Fac. of Inf. Technol., UAE Univ., Al-Ain, United Arab Emirates
  • fYear
    2011
  • fDate
    Nov. 29 2011-Dec. 2 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    As the size of the firewall security policies grows; the discarded packets by the default security rule affect significantly the system performance and become increasingly harmful in terms of filtering processing time. In this paper, we propose a mechanism to improve firewall performance through the early rejection of Denial of Service (DoS) traffic targeting the default security rule. To do that, the mechanism optimizes the order of the security policy filtering fields, using a traffic statistical scheme which is based on multilevel filtering modules, splay trees and hash tables. The proposed scheme can easily reject unwanted traffic in early stages as well as accept repeated packets with less memory accesses, and thus less overall packets matching time. The numerical results obtained by simulation demonstrated that the proposed mechanism reduced significantly the filtering processing time of DoS traffic targeting the firewall default security rule, compared to the related Self Adjusting Binary Search on Prefix Length (SA-BSPL) technique.
  • Keywords
    authorisation; computer network security; cryptography; information filtering; pattern matching; telecommunication traffic; tree searching; DoS traffic; denial of service traffic target; filtering processing time; firewall default security rule; hash table; memory access; multilevel filtering module; packet matching time; prefix length technique; security policy filtering field; selfadjusting binary search; splay trees based early packet rejection mechanism; Fires; Binary Search on Prefix Length; Default security rule; Early packet rejection; Firewall security policy; Hash Table; Packet classification; Splay Tree;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Forensics and Security (WIFS), 2011 IEEE International Workshop on
  • Conference_Location
    Iguacu Falls
  • Print_ISBN
    978-1-4577-1017-9
  • Electronic_ISBN
    978-1-4577-1018-6
  • Type

    conf

  • DOI
    10.1109/WIFS.2011.6123123
  • Filename
    6123123