An MTIDD based firewall: Using decision diagrams for packet filtering

Mikkel Christiansen, Emmanuel Fleury

Research output: Contribution to journalJournal articleResearchpeer-review

13 Citations (Scopus)

Abstract

This paper explores the use of Interval Decision Diagrams (IDDs) as the central structure of a firewall packet filtering mechanism. This is done by first relating the packet filtering problem to predicate logic, then implementing a prototype which is used in an empirical evaluation. The main benefits of the IDD structure are that it provides access to boolean algebra over filters, efficient classification time, and potentially a compact representation. Results from the empirical evaluation shows that IDDs are scalable in terms of memory usage: a 50,000 rule filter requires only 3MB of memory, and efficient for packet classification: it is able to handle more rules than the schemes it was compared to without causing a degradation in performance.
Original languageEnglish
JournalTelecommunications Systems
Volume27
Issue number2-4
Pages (from-to)297-319
Number of pages22
ISSN1018-4864
Publication statusPublished - 2004

Keywords

  • Packet Classification, Firewall, Traffic Filtering, Decision Diagrams

Fingerprint

Dive into the research topics of 'An MTIDD based firewall: Using decision diagrams for packet filtering'. Together they form a unique fingerprint.

Cite this