Dynamic Allocation and Hash Table Based Match Algorithms for Firewall Rules

DUAN Haixin,WU Jianping,LI Xing
DOI: https://doi.org/10.3321/j.issn:1000-0054.2001.01.025
2001-01-01
Abstract:Throughput and management issues arise when firewalls are applied in large transit networks. The manual configuration of large numbers of firewalls distributed in many access points can not provide open and dynamic environment and the large number of filtering rules decreases each firewall's throughput. Management can be improved using algorithms to automatically allocate global filtering rules to individual firewalls and to dynamically configure all of the firewalls according to the results of intrusion detection systems and search engines. The throughput of individual firewalls can be improved using a hash table based rule matching algorithm, which reduces the time complexity from O(N) to O(1) for transit networks, and therefore, increases the firewall throughput.
What problem does this paper attempt to address?