发明名称 REORDERING A FIREWALL RULE BASE ACCORDING TO USAGE STATISTICS
摘要 A computer implemented method of reducing central processing unit (CPU) usage of a firewall by safe reordering a current firewall's rule-base exhibiting N rules. The method comprising: receiving rule usage statistics exhibiting usage frequency of each rule on the current firewall's rule-base; calculating a rules matched per packet (RMPP) parameter, being a summation of products of each rule identifier and the corresponding usage frequency for all the N rules; determining an alternative order of the rule base by repositioning rules, wherein the repositioned rules perform the same action on the firewall, or wherein the repositioned rules act on disjoint sets of network connections, and wherein the repositioning results in a reduction of the RMPP of the reordered rule base, thereby reducing the CPU usage of the firewall in implementing the alternative order of rules.
申请公布号 US2009172800(A1) 申请公布日期 2009.07.02
申请号 US20080344231 申请日期 2008.12.25
申请人 WOOL AVISHAI 发明人 WOOL AVISHAI
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址