Optimizing Packet Filter Firewall using Duple Decision Scheme

Authors

  • Anshu Aneja Author
  • Vivek Thapar Author

Keywords:

Access List, BDD, Firewall, Multidimensional Filtering, Packet Filtering, Protocol Analyzer, Rule based Selection

Abstract

Network firewalls can use a database of rules to decide which packets will be allowed to move in and out and from one network onto another. However with the increase in size of rule list, it‟s very hard to manage and validate the rules, which can also increase the cost of rule lookup and that may add significantly to latency. This paper presents the study, design and implementation of a packet filter firewall using binary decision diagram which provides faster processing of packets while maintaining the integrity of the original security policy. Duple Decision Scheme or Ordered binary decision diagrams (OBDD) is an efficient and effective method of representing and manipulating Boolean expressions and can be used for the representation of the rule set. This paper explores how OBDD can be used to device methods that can help in validation and analysis of rules to improve performance, and facilitate hardware support.

References

Downloads

Published

2013-06-13

Issue

Section

Articles