Paper
17 January 1997 Performance optimization of internet firewalls
Tzi-cker Chiueh, Allen Ballman
Author Affiliations +
Abstract
Internet firewalls control the data traffic in and out of an enterprise network by checking network packets against a set of rules that embodies an organization's security policy. Because rule checking is computationally more expensive than routing-table look-up, it could become a potential bottleneck for scaling up the performance of IP routers, which typically implement firewall functions in software. in this paper, we analyzed the performance problems associated with firewalls, particularly packet filters, propose a good connection cache to amortize the costly security check over the packets in a connection, and report the preliminary performance results of a trace-driven simulation that show the average packet check time can be reduced by a factor of 2.5 at the least.
© (1997) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Tzi-cker Chiueh and Allen Ballman "Performance optimization of internet firewalls", Proc. SPIE 2915, Video Techniques and Software for Full-Service Networks, (17 January 1997); https://doi.org/10.1117/12.263388
Lens.org Logo
CITATIONS
Cited by 1 scholarly publication.
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Network security

Internet

Information security

Computer security

Computer science

Computer simulations

Back to Top