Back to Search
Start Over
Hybrid tree-rule firewall for high speed data transmission
- Source :
- IEEE transactions on cloud computing, 8(4):7452587, 1237-1249. IEEE
- Publication Year :
- 2020
-
Abstract
- Traditional firewalls employ listed rules in both configuration and process phases to regulate network traffic. However, configuring a firewall with listed rules may create rule conflicts, and slows down the firewall. To overcome this problem, we have proposed a Tree-rule firewall in our previous study. Although the Tree-rule firewall guarantees no conflicts within its rule set and operates faster than traditional firewalls, keeping track of the state of network connections using hashing functions incurs extra computational overhead. In order to reduce this overhead, we propose a hybrid Tree-rule firewall in this paper. This hybrid scheme takes advantages of both Tree-rule firewalls and traditional listed-rule firewalls. The GUIs of our Tree-rule firewalls are utilized to provide a means for users to create conflict-free firewall rules, which are organized in a tree structure and called 'tree rules'. These tree rules are later converted into listed rules that share the merit of being conflict-free. Finally, in decision making, the listed rules are used to verify against packet header information. The rules which have matched with most packets are moved up to the top positions by the core firewall. The mechanism applied in this hybrid scheme can significantly improve the functional speed of a firewall.
- Subjects :
- cloud network
Computer Networks and Communications
Network security
DMZ
Computer science
004 Data processing & computer science
QA75 Electronic computers. Computer science
Culture and Communities
Firewalls (computing), Cloud computing, IP networks, Field programmable gate arrays, Filtering, Ports (Computers)
02 engineering and technology
Cyber-security
Firewall (construction)
Stateful firewall
020204 information systems
Centre for Distributed Computing, Networking and Security
0202 electrical engineering, electronic engineering, information engineering
network security
Reverse connection
computer network
high speed firewall
business.industry
ComputerSystemsOrganization_COMPUTER-COMMUNICATIONNETWORKS
Firewall
020206 networking & telecommunications
AI and Technologies
Computer Science Applications
Context-based access control
Tree structure
Hardware and Architecture
Application firewall
Networks
business
Software
Information Systems
Computer network
Subjects
Details
- Language :
- English
- ISSN :
- 21687161
- Volume :
- 8
- Issue :
- 4
- Database :
- OpenAIRE
- Journal :
- IEEE transactions on cloud computing
- Accession number :
- edsair.doi.dedup.....5452434b79ccefcaf4b390909ca77f51