首页> 外文会议>ACM Symposium on Information, computer and communications security >Dynamic rule-ordering optimization for high-speed firewall filtering
【24h】

Dynamic rule-ordering optimization for high-speed firewall filtering

机译:动态规则排序优化,可实现高速防火墙过滤

获取原文
获取外文期刊封面目录资料

摘要

Packet filtering plays a critical role in many of the current high speed network technologies such as firewalls and IPSec devices. The optimization of firewall policies is critically important to provide high performance packet filtering particularly for high speed network security. Current packet filtering techniques exploit the characteristics of the filtering policies, but they do not consider the traffic behavior in optimizing their search data structures. This results in impractically high space complexity, which undermines the performance gain offered by these techniques. Also, these techniques offer upper bounds for the worst case search times; nevertheless, average case scenarios are not necessarily optimized. Moreover, the types of packet filtering fields used in most of these techniques are limited to IP header fields and cannot be generalized to cover transport and application layer filtering.In this paper, we present a novel technique that utilizes Internet traffic characteristics to optimize firewall filtering policies. The proposed technique timely adapts to the traffic conditions using actively calculated statistics to dynamically optimize the ordering of packet filtering rules. The rule importance in traffic matching as well as its dependency on other rules are both considered in our optimization algorithm. Through extensive evaluation experiments using simulated and real Internet traffic traces, the proposed mechanism is shown to be efficient and easy to deploy in practical firewall implementations.
机译:数据包过滤在许多当前的高速网络技术(例如防火墙和IPSec设备)中扮演着至关重要的角色。防火墙策略的优化对于提供高性能的数据包筛选(特别是对于高速网络安全性)至关重要。当前的数据包过滤技术利用了过滤策略的特征,但是在优化其搜索数据结构时并未考虑流量行为。这导致不切实际的高空间复杂性,从而破坏了这些技术所提供的性能。同样,这些技术为最坏情况的搜索时间提供了上限。但是,一般情况下的场景并不一定要优化。此外,大多数这些技术中使用的数据包筛选字段的类型仅限于IP头字段,并且不能一概而论以涵盖传输和应用程序层筛选。本文中,我们提出了一种利用Internet流量特性来优化防火墙筛选的新技术。政策。所提出的技术使用主动计算的统计信息来动态地优化分组过滤规则的排序,从而适时地适应交通状况。我们在优化算法中同时考虑了流量匹配中规则的重要性及其对其他规则的依赖性。通过使用模拟和真实Internet流量跟踪进行的广泛评估实验,表明该机制在实际的防火墙实现中是高效且易于部署的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号