Firewalls White Papers
Complete Redundancy Detection in Firewalls
Overview Firewalls are safety-critical systems that secure most private networks. The function of a firewall is to examine each incoming and outgoing packet and decide whether to accept or to discard the packet. This decision is made according to a sequence of rules, where some rules may be redundant. Redundant rules significantly degrade the performance of firewalls. This paper gives a necessary and sufficient condition for identifying all redundant rules. Based on this condition, it categorizes redundant rules into upward redundant rules and downward redundant rules. It also presents methods for detecting the two types of redundant rules respectively.
| Publisher | International Federation for Information Processing | File Format | |
|---|---|---|---|
| Date Published | June 2005 | ||
| Format | White Papers | ||
| Topics | |||



