KFUPM ePrints

A Heuristic Approach for Firewall Policy Optimization

El-Alfy, E.-S.M. (2007) A Heuristic Approach for Firewall Policy Optimization. In: IEEE International Conference on Advanced Communication Technology (ICACT’07).

[img]PDF
Restricted to Registered users only

28Kb

Abstract

A primary goal of this paper is to develop a heuristic approach based on genetic algorithms to enhance the firewall performance. Typical firewall policies may have thousands of rules and determining an optimal rule order that minimizes the average number of rule comparisons while maintaining the policy integrity is proven to be NP-hard. This problem is formulated as a binary integer program for which an optimal solution is obtained using the branch-and-bound technique. Then an alternative solution approach is devised based on genetic algorithms. Several experiments are conducted to evaluate the effectiveness of the proposed approach as compared to other rule-ordering techniques. Empirical results show the potential and flexibility of the proposed approach.



Item Type:Conference or Workshop Item (Paper)
Date:February 2007
Subjects:Computer
Divisions:College Of Computer Sciences and Engineering > Information and Computer Science Dept
Creators:El-Alfy, E.-S.M.
Email:alfy@kfupm.edu.sa
ID Code:10698
Deposited By:Dr. EL-SAYED EL-ALFY
Deposited On:25 Jun 2008 14:55
Last Modified:12 Apr 2011 13:14

Repository Staff Only: item control page