Methods, systems, and computer program products for network firewall policy optimization
Patent
·
OSTI ID:1028661
- Winston-Salem, NC
- Duxbury, MA
Methods, systems, and computer program products for firewall policy optimization are disclosed. According to one method, a firewall policy including an ordered list of firewall rules is defined. For each rule, a probability indicating a likelihood of receiving a packet matching the rule is determined. The rules are sorted in order of non-increasing probability in a manner that preserves the firewall policy.
- Research Organization:
- Wake Forest University (Winston-Salem, NC)
- Sponsoring Organization:
- USDOE
- DOE Contract Number:
- FG02-03ER25581
- Assignee:
- Wake Forest University (Winston-Salem, NC)
- Patent Number(s):
- 8,042,167
- Application Number:
- 11/390,976
- OSTI ID:
- 1028661
- Country of Publication:
- United States
- Language:
- English
Various optimizers for single-stage production
|
journal | March 1956 |
A Full Bandwidth ATM Firewall
|
book | January 2000 |
Firewall Policy Advisor for Anomaly Discovery and Rule Editing
|
book | January 2003 |
Sequencing Jobs to Minimize Total Weighted Completion Time Subject to Precedence Constraints
|
book | January 1978 |
Optimization and Approximation in Deterministic Sequencing and Scheduling: a Survey
|
book | January 1979 |
LSMAC vs. LSNAT: Scalable cluster‐based Web servers
|
journal | November 2000 |
Network firewalls
|
journal | September 1994 |
Design and evaluation of a high-performance ATM firewall switch and its applications
|
journal | June 1999 |
On the self-similar nature of Ethernet traffic (extended version)
|
journal | January 1994 |
Router plugins: a software architecture for next-generation routers
|
journal | January 2000 |
A parallel packet screen for high speed networks
|
conference | January 1999 |
Preventing denial of service attacks on quality of service
|
conference | June 2001 |
Development framework for firewall processors
|
conference | January 2002 |
An unavailability analysis of firewall sandwich configurations
|
conference | October 2001 |
Fast firewall implementations for software and hardware-based routers
|
conference | November 2001 |
Detecting and resolving packet filter conflicts
|
conference | January 2000 |
Fast packet classification for two-dimensional conflict-free filters
|
conference | January 2001 |
Balancing Trie-Based Policy Representations for Network Firewalls
|
conference | January 2006 |
Modeling and Management of Firewall Policies
|
journal | April 2004 |
Counting linear extensions is #P-complete
|
conference | January 1991 |
Small forwarding tables for fast routing lookups
|
journal | October 1997 |
Fast and scalable layer four switching
|
journal | October 1998 |
Analysis of a heuristic for full trie minimization
|
journal | September 1981 |
Algorithms for trie compaction
|
journal | June 1984 |
On self-organizing sequential search heuristics
|
journal | February 1976 |
Complexity of Scheduling under Precedence Constraints
|
journal | February 1978 |
Using IDDs for Packet Filtering
|
journal | June 2002 |
Similar Records
Method, systems, and computer program products for implementing function-parallel network firewall
Firewall Architectures for High-Speed Networks: Final Report
Integrated Scalable Parallel Firewall and Intrusion Detection System for High-Speed Networks
Patent
·
2011
·
OSTI ID:1028984
Firewall Architectures for High-Speed Networks: Final Report
Technical Report
·
2007
·
OSTI ID:924750
Integrated Scalable Parallel Firewall and Intrusion Detection System for High-Speed Networks
Technical Report
·
2009
·
OSTI ID:963374