Packet filtering and processing rules management in firewalls and security gateways has become commonplace in increasingly complex networks. On one side there is a need to maintain the logic of high level policies, which requires administrators to implement and update a large amount of filtering rules while keeping them conflict-free, that is, avoiding security inconsistencies. On the other side, traffic adaptive optimization of large rule lists is useful for general purpose computers used as filtering devices, without specific designed hardware, to face growing link speeds and to harden filtering devices against DoS and DDoS attacks. Our work joins the two issues in an innovative way and defines a traffic adaptive algorithm to find conflict-free optimized rule sets, by relying on information gathered with traffic logs. The proposed approach suits current technology architectures and exploits available features, like traffic log databases, to minimize the impact of ACO development on the packet filtering devices. We demonstrate the benefit entailed by the proposed algorithm through measurements on a test bed made up of real-life, commercial packet filtering devices.

Adaptive conflict-free optimization of rule sets for network security packet filtering devices / Baiocchi, Andrea; Gianluca, Maiolini; Annachiara, Mingo; Daniele, Goretti. - In: JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS. - ISSN 2090-7141. - 2015:(2015), pp. 1-17. [10.1155/2015/872326]

Adaptive conflict-free optimization of rule sets for network security packet filtering devices

BAIOCCHI, Andrea;
2015

Abstract

Packet filtering and processing rules management in firewalls and security gateways has become commonplace in increasingly complex networks. On one side there is a need to maintain the logic of high level policies, which requires administrators to implement and update a large amount of filtering rules while keeping them conflict-free, that is, avoiding security inconsistencies. On the other side, traffic adaptive optimization of large rule lists is useful for general purpose computers used as filtering devices, without specific designed hardware, to face growing link speeds and to harden filtering devices against DoS and DDoS attacks. Our work joins the two issues in an innovative way and defines a traffic adaptive algorithm to find conflict-free optimized rule sets, by relying on information gathered with traffic logs. The proposed approach suits current technology architectures and exploits available features, like traffic log databases, to minimize the impact of ACO development on the packet filtering devices. We demonstrate the benefit entailed by the proposed algorithm through measurements on a test bed made up of real-life, commercial packet filtering devices.
2015
Firewall; classification; policy; performance; resolution
01 Pubblicazione su rivista::01a Articolo in rivista
Adaptive conflict-free optimization of rule sets for network security packet filtering devices / Baiocchi, Andrea; Gianluca, Maiolini; Annachiara, Mingo; Daniele, Goretti. - In: JOURNAL OF COMPUTER NETWORKS AND COMMUNICATIONS. - ISSN 2090-7141. - 2015:(2015), pp. 1-17. [10.1155/2015/872326]
File allegati a questo prodotto
File Dimensione Formato  
Baiocchi_Adaptive-conflict-free_2015.pdf

accesso aperto

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Creative commons
Dimensione 2.48 MB
Formato Adobe PDF
2.48 MB Adobe PDF

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/782107
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? 0
social impact