• DocumentCode
    971033
  • Title

    A general framework for benchmarking firewall optimization techniques

  • Author

    Misherghi, Ghassan ; Yuan, Lihua ; Su, Zhendong ; Chuah, Chen-Nee ; Chen, Hao

  • Volume
    5
  • Issue
    4
  • fYear
    2008
  • fDate
    12/1/2008 12:00:00 AM
  • Firstpage
    227
  • Lastpage
    238
  • Abstract
    Firewalls are among the most pervasive network security mechanisms, deployed extensively from the borders of networks to end systems. The complexity of modern firewall policies has raised the computational requirements for firewall implementations, potentially limiting the throughput of networks. Administrators currently rely on ad hoc solutions to firewall optimization. To address this problem, a few automatic firewall optimization techniques have been proposed, but there has been no general approach to evaluate the optimality of these techniques. In this paper we present a general framework for rule-based firewall optimization. We give a precise formulation of firewall optimization as an integer programming problem and show that our framework produces optimal reordered rule sets that are semantically equivalent to the original rule set. Our framework considers the complex interactions among the rules in firewall configurations and relies on a novel partitioning of the packet space defined by the rules themselves. For validation, we employ this framework on real firewall rule sets for a quantitative evaluation of existing heuristic approaches. Our results indicate that the framework is general and faithfully captures performance benefits of firewall optimization heuristics.
  • Keywords
    authorisation; benchmark testing; computer networks; integer programming; telecommunication security; ubiquitous computing; ad hoc solution; automatic rule-based firewall optimization heuristic technique; benchmarking framework; integer programming problem; packet space partitioning; pervasive network security mechanism; Access protocols; Computer networks; Delay; Digital filters; Filtering; Hardware; Inspection; Internet; Linear programming; Throughput; Firewall optimization, ACL optimization, firewall management, ACL partitioning;
  • fLanguage
    English
  • Journal_Title
    Network and Service Management, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1932-4537
  • Type

    jour

  • DOI
    10.1109/TNSM.2009.041104
  • Filename
    5010446