An MTIDD Based Firewall Using Decision Diagrams for Packet Filtering - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Telecommunication Systems Année : 2004

An MTIDD Based Firewall Using Decision Diagrams for Packet Filtering

Résumé

This paper explores the use of Multi-Terminal Interval Decision Diagrams (MTIDDs) as the central structure of a firewall packet filtering mechanism. This is done by first relating the packet filtering problem to predicate logic, then implementing a prototype which is used in an empirical evaluation. The main benefits of the MTIDD structure are that it provides access to Boolean algebra over filters, efficient classification time, and a compact representation. Results from the empirical evaluation shows that MTIDDs are scalable in terms of memory usage: a 50,000 rule filter requires only 3MB of memory, and efficient for packet classification: it is able to handle more rules than the schemes it was compared to without causing a degradation in performance.
Fichier principal
Vignette du fichier
CF-ts04.pdf (269.01 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00350221 , version 1 (06-01-2009)

Identifiants

Citer

Mikkel Christiansen, Emmanuel Fleury. An MTIDD Based Firewall Using Decision Diagrams for Packet Filtering. Telecommunication Systems, 2004, 27 (2-4), pp.297-319. ⟨10.1023/B:TELS.0000041013.23205.0f⟩. ⟨hal-00350221⟩

Collections

CNRS
80 Consultations
336 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More