loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
10th IEEE Symposium on Computers and Communications (ISCC'05)
Trie-Based Policy Representations for Network Firewalls
Cartagena, Murcia, Spain
June 27-June 30
ISBN: 0-7695-2373-0
Errin W. Fulp, Wake Forest University
Stephen J. Tarsa, Wake Forest University

Network firewalls remain the forefront defense for most computer systems. These critical devices filter traffic by comparing arriving packets to a list of rules, or security policy, in a sequential manner. Unfortunately packet filtering in this fashion can result in significant traffic delays, which is problematic for applications that require strict Quality of Service (QoS) guarantees. Given this demanding environment, new methods are needed to increase network firewall performance.

This paper introduces a new technique for representing a security policy that maintains policy integrity and provides more efficient processing. The policy is represented as an n-ary retrieval tree, also referred to as a trie. The worst case processing requirement for the policy trie is a fraction compared a list representation, which only considers rules individually (1/5 the processing for TCP/IP networks). Furthermore unlike other representations, the nary trie developed in this paper can be proven to maintain policy integrity. The creation of policy trie structures is discussed in detail and their performance benefits are described theoretically and validated empirically.

Citation:
Errin W. Fulp, Stephen J. Tarsa, "Trie-Based Policy Representations for Network Firewalls," iscc, pp.434-441, 10th IEEE Symposium on Computers and Communications (ISCC'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.