Trie-based policy representations for network firewalls

被引:6
|
作者
Fulp, EW [1 ]
Tarsa, SJ [1 ]
机构
[1] Wake Forest Univ, Dept Comp Sci, Winston Salem, NC 27109 USA
关键词
D O I
10.1109/ISCC.2005.149
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network firewalls remain the forefront defense for most computer systems. These critical devices filter traffic by comparing arriving packets to a list of rules, or security policy, in a sequential manner Unfortunately packet filtering in this fashion can result in significant traffic delays, which is problematic for applications that require strict Quality of Service (QoS) guarantees. Given this demanding environment, new methods are needed to increase network firewall performance. This paper introduces a new technique for representing a security policy that maintains policy integrity and provides more efficient processing. The policy is represented as an n-ary retrieval tree, also referred to as a trie. The worst case processing requirement for the policy trie is a fraction compared a list representation, which only considers rules individually (1/5 the processing for TCP/IP networks). Furthermore unlike other representations, the nary trie developed in this paper can be proven to maintain policy integrity. The creation of policy trie structures is discussed in detail and their performance benefits are described theoretically and validated empirically.
引用
收藏
页码:434 / 441
页数:8
相关论文
共 50 条
  • [21] Enhancing Genetic Algorithms by a Trie-Based Complete Solution Archive
    Raidl, Guenther R.
    Hu, Bin
    EVOLUTIONARY COMPUTATION IN COMBINATORIAL OPTIMIZATION, PROCEEDINGS, 2010, 6022 : 239 - 251
  • [22] IncMD: Incremental trie-based structural motif discovery algorithm
    Badr, Ghada
    Al-Turaiki, Isra
    Turcotte, Marcel
    Mathkour, Hassan
    JOURNAL OF BIOINFORMATICS AND COMPUTATIONAL BIOLOGY, 2014, 12 (05)
  • [23] ITOC: An Improved Trie-Based Algorithm for Online Packet Classification
    Li, Yifei
    Wang, Jinlin
    Chen, Xiao
    Wu, Jinghong
    APPLIED SCIENCES-BASEL, 2021, 11 (18):
  • [24] An Improved Trie-based Name Lookup Scheme for Named Data Networking
    Li, Dagang
    Li, Junmao
    Du, Zheng
    2016 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATION (ISCC), 2016, : 1294 - 1296
  • [25] Trie-Hashimoto: State Trie-Based Proof-of-Work Mining for Optimizing Blockchain Storage
    Kim, Jae-Yun
    Lee, Junmo
    Moon, Soo-Mook
    IEEE ACCESS, 2024, 12 : 18315 - 18329
  • [26] Trie-Join: Efficient Trie-based String Similarity Joins with Edit-Distance Constraints
    Wang, Jiannan
    Feng, Jianhua
    Li, Guoliang
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2010, 3 (01): : 1219 - 1230
  • [27] Web-based document classification using a trie-based index structure
    Park, Jeahyun
    Park, Juyoung
    Choi, Joongmin
    PROCEEDING OF THE 2007 IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE AND INTELLIGENT AGENT TECHNOLOGY, WORKSHOPS, 2007, : 52 - 55
  • [28] A SRAM-based Architecture for Trie-based IP Lookup Using FPGA
    Le, Hoang
    Jiang, Weirong
    Prasanna, Viktor K.
    PROCEEDINGS OF THE SIXTEENTH IEEE SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES, 2008, : 33 - 42
  • [29] Parallel-search trie-based scheme for fast IP lookup
    Rojas-Cessa, Roberto
    Ramesh, Lakshmi
    Dong, Ziqian
    Cai, Lin
    Ansari, Nirwan
    GLOBECOM 2007: 2007 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-11, 2007, : 210 - 214
  • [30] Distributed Key Management in Dynamic Outsourced Databases: a Trie-Based Approach
    El-Khoury, V.
    Bennani, N.
    Ouksel, A. M.
    2009 FIRST INTERNATIONAL CONFERENCE ON ADVANCES IN DATABASES, KNOWLEDGE, AND DATA APPLICATIONS, 2009, : 56 - +