A heuristic approach for firewall policy optimization

被引:5
|
作者
El-Alfy, El-Sayed M. [1 ]
机构
[1] King Fahd Univ Petr & Minerals, Coll Comp Sci & Engn, Dhahran 31261, Saudi Arabia
关键词
network security; firewalls; access control; and genetic algorithms;
D O I
10.1109/ICACT.2007.358716
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
A primary goal of this paper is to develop a heuristic approach based on genetic algorithms to enhance the firewall performance. Typical firewall policies may have thousands of rules and determining an optimal rule order that minimizes the average number of rule comparisons while maintaining the policy integrity is proven to be NP-hard. This problem is formulated as a binary integer program for which an optimal solution is obtained using the branch-and-bound technique. Then. an alternative solution approach is devised based on genetic algorithms. Several experiments are conducted to evaluate the effectiveness of the proposed approach as compared to other rule-ordering techniques. Empirical results show the potential and flexibility of the proposed approach.
引用
收藏
页码:1782 / 1787
页数:6
相关论文
共 50 条
  • [21] HEURISTIC APPROACH TO TOTAL DISTRIBUTION SYSTEM OPTIMIZATION
    FEINBERG, IO
    OPERATIONS RESEARCH, 1975, 23 : B407 - B407
  • [22] Bayesian heuristic approach to global optimization and examples
    Jonas Mockus
    Journal of Global Optimization, 2002, 22 : 191 - 203
  • [23] Bayesian heuristic approach to global optimization and examples
    Mockus, J
    JOURNAL OF GLOBAL OPTIMIZATION, 2002, 22 (1-4) : 191 - 203
  • [24] Optimization of cyclic production systems: A heuristic approach
    Chauvet, F
    Herrmann, JW
    Proth, JM
    IEEE TRANSACTIONS ON ROBOTICS AND AUTOMATION, 2003, 19 (01): : 150 - 154
  • [25] Environmental Adaption Method: A Heuristic Approach for Optimization
    Chandila, Anuj
    Tiwari, Shailesh
    Mishra, K. K.
    Punhani, Akash
    INTERNATIONAL JOURNAL OF APPLIED METAHEURISTIC COMPUTING, 2019, 10 (01) : 107 - 131
  • [26] A mixed evolutionary/heuristic approach to shape optimization
    Le Riche, R
    Cailletaud, G
    INTERNATIONAL JOURNAL FOR NUMERICAL METHODS IN ENGINEERING, 1998, 41 (08) : 1463 - 1484
  • [27] Heuristic approach to solution of industrial optimization problems
    Absaloms, Heywood
    Iwami, Yoshio
    Tomikawa, Takehiko
    IEEE AFRICON Conference, 1999, 1 : 127 - 130
  • [28] Global optimization using Bayesian heuristic approach
    Lin, SM
    Tian, FZ
    Lu, YC
    PROCEEDINGS OF THE 3RD WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-5, 2000, : 3470 - 3473
  • [29] AN HEURISTIC APPROACH FOR FINITE-TIME MAINTENANCE POLICY
    JAYABALAN, V
    CHAUDHURI, D
    INTERNATIONAL JOURNAL OF PRODUCTION ECONOMICS, 1992, 27 (03) : 251 - 256
  • [30] Policy segmentation for intelligent firewall testing
    El-Atawy, A
    Ibrahim, K
    Hamed, H
    Al-Shaer, E
    2005 FIRST WORKSHOP ON SECURE NETWORK PROTOCOLS (NPSEC), 2005, : 67 - 72