Algorithms for Analysing Firewall and Router Access Lists
Scott Hazelhurst
Abstract
Network firewalls and routers use a rule database to decide which packets will be allowed from one network onto another. By filtering packets the firewalls and routers can improve security and performance. However, as the size of the rule list increases, it becomes difficult to maintain and validate the rules, and lookup latency may increase significantly. Ordered binary decision diagrams (BDDs) - a compact method of representing and manipulating boolean expressions - are a potential method of representing the rules. This paper presents a new algorithm for representing such lists as a BDD and then shows how the resulting boolean expression can be used to analyse rule sets.
Create a lesson
Related papers
RUN-O-RAN: An O-RAN-Native Architecture Enabling Cooperative Uplink Localization
Viola Bernazzoli, Alberto Ceresoli, Ilario Filippini
NS3Learn: Transferring 5G NR Mode-2 Reception Realism from ns-3 to the Veins/SUMO Stack for Connected-Vehicle Safety Assessment
Rasheed Bello, Arthur Mukwaya, Gurcan Comert et al.
Value-Based Massive Access through Goal-Oriented Irregular Repetition Slotted ALOHA
Pietro Talli, Andrea Munari, Federico Mason et al.
STR-Agent: An LLM-Driven Agent for QoS-Aware Routing in LEO Satellite Networks
Bowen Lu, Mugen Peng, Yaohua Sun et al.
PyStream: Enhancing Video Streaming Evaluation
Samuel Radler, Leon Prüller, Emanuele Artioli et al.
Taming the Agentic RAN: Stability-Guaranteed Arbitration of Autonomous AI Agents in O-RAN
Seyed Bagher Hashemi Natanzi, Bo Tang