Dynamic Update of Firewall Policy Based on MFDT

Wenhui Chen,Weiping Wang,Zhepeng Li,Huaping Chen
DOI: https://doi.org/10.1109/iccias.2006.295436
2006-01-01
Abstract:To improve the filtering speed of firewall, researchers have proposed many expression tools for firewall policy. However, these tools share a limitation: not compatible with dynamic updating of firewall policy. Therefore, this paper suggests marked firewall decision trees (MFDT) model. MFDT can handle not only the package filtering but also dynamically response to the updating of original policies. First of all, it is given the definition of MFDT. For three situation of policy change: adding, modifying and deleting of rules, corresponding updating algorithms of MFDT are given. In the end, MFDT's integrality and complexity are proved
What problem does this paper attempt to address?