A heuristic approach for firewall policy optimization

被引:5
|
作者
El-Alfy, El-Sayed M. [1 ]
机构
[1] King Fahd Univ Petr & Minerals, Coll Comp Sci & Engn, Dhahran 31261, Saudi Arabia
关键词
network security; firewalls; access control; and genetic algorithms;
D O I
10.1109/ICACT.2007.358716
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
A primary goal of this paper is to develop a heuristic approach based on genetic algorithms to enhance the firewall performance. Typical firewall policies may have thousands of rules and determining an optimal rule order that minimizes the average number of rule comparisons while maintaining the policy integrity is proven to be NP-hard. This problem is formulated as a binary integer program for which an optimal solution is obtained using the branch-and-bound technique. Then. an alternative solution approach is devised based on genetic algorithms. Several experiments are conducted to evaluate the effectiveness of the proposed approach as compared to other rule-ordering techniques. Empirical results show the potential and flexibility of the proposed approach.
引用
收藏
页码:1782 / 1787
页数:6
相关论文
共 50 条
  • [1] F/Wvis: Hierarchical Visual Approach for Effective Optimization of Firewall Policy
    Kim, Taeyong
    Kwon, Taewoong
    Lee, Jun
    Song, Jungsuk
    IEEE ACCESS, 2021, 9 : 105989 - 106004
  • [2] F/Wvis: Hierarchical Visual Approach for Effective Optimization of Firewall Policy
    Kim, Taeyong
    Kwon, Taewoong
    Lee, Jun
    Song, Jungsuk
    IEEE Access, 2021, 9 : 105989 - 106004
  • [3] On autonomic optimization of firewall policy organization
    Hamed, Hazem
    Al-Shaer, Ehab
    JOURNAL OF HIGH SPEED NETWORKS, 2006, 15 (03) : 209 - 227
  • [4] A policy-based approach to firewall management
    Caldeira, F
    Monteiro, E
    NETWORK CONTROL AND ENGINEERING FOR QOS, SECURITY AND MOBILITY, 2003, 107 : 115 - 126
  • [5] Firewall Policy Queries
    Liu, Alex X.
    Gouda, Mohamed G.
    IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2009, 20 (06) : 766 - 777
  • [6] Establishing firewall policy
    Cobb, S
    SOUTHCON/96 - CONFERENCE RECORD, 1996, : 198 - 205
  • [7] Firewall policy diagram: Structures for firewall behavior comprehension
    Clark, Patrick G
    Agah, Arvin
    International Journal of Network Security, 2015, 17 (02) : 150 - 159
  • [8] AN APPROACH TO OPTIMIZATION WITH HEURISTIC METHODS OF SCHEDULING
    CLIFFE, RW
    MACMANUS, BR
    INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 1980, 18 (04) : 479 - 490
  • [9] AN HEURISTIC APPROACH TO RENEWABLE ENERGY OPTIMIZATION
    Walker, Andy
    ES2009: PROCEEDINGS OF THE ASME 3RD INTERNATIONAL CONFERENCE ON ENERGY SUSTAINABILITY, VOL 1, 2009, : 419 - 426
  • [10] Optimization of firewall rules
    Katic, Tihomir
    Pale, Predrag
    PROCEEDINGS OF THE ITI 2007 29TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY INTERFACES, 2007, : 685 - +