Invention Grant
- Patent Title: Reordering a firewall rule base according to usage statistics
- Patent Title (中): 根据使用统计信息重新排列防火墙规则库
-
Application No.: US12344231Application Date: 2008-12-25
-
Publication No.: US08418240B2Publication Date: 2013-04-09
- Inventor: Avishai Wool
- Applicant: Avishai Wool
- Applicant Address: IL Ramat Gan
- Assignee: Algorithmic Security (Israel) Ltd.
- Current Assignee: Algorithmic Security (Israel) Ltd.
- Current Assignee Address: IL Ramat Gan
- Agency: Fleit Gibbons Gutman Bongini & Bianco PL
- Agent Martin Fleit; Paul D. Bianco
- Main IPC: G06F9/00
- IPC: G06F9/00

Abstract:
A computer implemented method of reducing central processing unit (CPU) usage of a firewall by safe reordering a current firewall's rule-base exhibiting N rules. The method comprising: receiving rule usage statistics exhibiting usage frequency of each rule on the current firewall's rule-base; calculating a rules matched per packet (RMPP) parameter, being a summation of products of each rule identifier and the corresponding usage frequency for all the N rules; determining an alternative order of the rule base by repositioning rules, wherein the repositioned rules perform the same action on the firewall, or wherein the repositioned rules act on disjoint sets of network connections, and wherein the repositioning results in a reduction of the RMPP of the reordered rule base, thereby reducing the CPU usage of the firewall in implementing the alternative order of rules.
Public/Granted literature
- US20090172800A1 REORDERING A FIREWALL RULE BASE ACCORDING TO USAGE STATISTICS Public/Granted day:2009-07-02
Information query