作者: M.G. Gouda , X.-Y.A. Liu
DOI: 10.1109/ICDCS.2004.1281597
关键词:
摘要: A firewall is often placed at the entrance of each private network in Internet. The function a to examine packet that passes through and decide whether accept allow it proceed or discard packet. usually designed as sequence rules. To make decision concerning some packets, rules are compared, one by one, with until rule found be satisfied packet: this determines fate We present first ever method for designing consistent, complete, compact. Consistency means ordered correctly, completeness every satisfies least firewall, compactness has no redundant Our starts diagram (FDD, short) whose consistency can checked systematically (by an algorithm). then apply five algorithms FDD generate, reduce simplify target while maintaining original FDD.