×

METHODS, SYSTEMS, AND COMPUTER READABLE MEDIA FOR ADAPTIVE PACKET FILTERING

  • US 20110055916A1
  • Filed: 08/30/2010
  • Published: 03/03/2011
  • Est. Priority Date: 08/28/2009
  • Status: Active Grant
First Claim
Patent Images

1. A method for adaptive packet filtering, the method comprising:

  • identifying at least one subset of rules in an ordered set of firewall packet filtering rules that defines a firewall policy such that the at least one subset contains disjoint rules, where disjoint rules are defined as rules whose order can be changed without changing the integrity of the firewall policy;

    sorting the rules in the at least one subset to statistically decrease the number of comparisons that will be applied to each packet that a firewall encounters; and

    filtering packets at the firewall using the sorted rules in the at least one subset by comparing each packet to each of the sorted rules in the at least one subset until the packet is allowed or denied and ceasing the comparing for the packet in response to the packet being allowed or denied and thereby achieving sub-linear searching for the packets filtered using the sorted rules in at least one subset.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×