Sciweavers

AICT
2010
IEEE

A Simplified Method for Optimising Sequentially Processed Access Control Lists

12 years 8 months ago
A Simplified Method for Optimising Sequentially Processed Access Control Lists
Among the various options for implementing Internet packet filters in the form of Access Control Lists (ACLs), is the intuitive – but potentially crude – method of processing the ACL rules in sequential order. Although such an approach leads to variable processing times for each packet matched against the ACL, it also offers the opportunity to reduce this time by reordering its rules in response to changing traffic characteristics. A number of heuristics exist for optimising rule order in sequentially processed ACLs and the most efficient of these can be shown to have a beneficial effect in a majority of cases and for ACLs with relatively small numbers of rules. This paper presents an enhancement to this algorithm by reducing part of its complexity. Although the simplification involved leads to an instantaneous lack of accuracy, the longterm trade-off between processing speed and performance can be seen, through experimentation, to be positive. This improvement, though small, is co...
Vic Grout, John Davies
Added 23 Aug 2011
Updated 23 Aug 2011
Type Journal
Year 2010
Where AICT
Authors Vic Grout, John Davies
Comments (0)