Bimonthly    Since 1986
ISSN 1004-9037
Publication Details
Edited by: Editorial Board of Journal of Data Acquisition and Processing
P.O. Box 2704, Beijing 100190, P.R. China
Sponsored by: Institute of Computing Technology, CAS & China Computer Federation
Undertaken by: Institute of Computing Technology, CAS
Published by: SCIENCE PRESS, BEIJING, CHINA
Distributed by:
China: All Local Post Offices
 
   
      09 May 2023, Volume 38 Issue 3
    Article

    MODIFIED TREE RULE FIREWALL FOR REMOVING REDUNDANT AND SHADOWING RULES IN CLOUD FIREWALL POLICY
    Dhwani Hakani1, Palvinder Singh Mann2*
    Journal of Data Acquisition and Processing, 2023, 38 (3): 727-742 . 

    Abstract

    Most private networks are secured by firewalls, which are crucial for safety. A firewall aims to inspect every inward and outgoing traffic before deciding whether to allow it. The rule-based firewall is a frequently used conventional firewall. However, conventional Listed-Rule firewalls have limits when it comes to task performance and is ineffective when used with some networks that have very large firewall rule sets. This paper suggests a model firewall design, "Tree-Rule Firewall," which has advantages and works with expansive networks like "cloud". This paper proposes a modified tree rule firewall (MTRFcloud) for removing redundant and shadowing rules, improving cloud network security. This work first generates a tree rule firewall for the corresponding firewall policy. The suggested modified tree rule firewall does not produce redundant rules and efficiently finds the shadow rules. Then, a modified Tree-Rule firewall that manages firewall rules was tested in a cloud setting. It is shown that the updated Tree-Rule firewall provides faster processing and greater network security. With a big network, like a cloud network, the modified Tree-Rule firewall is simpler to construct and efficiently removes the redundant and shadow rules.

    Keyword

    Firewall, Tree rules, cloud security, redundant rule, shadowing rule


    PDF Download (click here)

SCImago Journal & Country Rank

ISSN 1004-9037

         

Home
Editorial Board
Author Guidelines
Subscription
Journal of Data Acquisition and Processing
Institute of Computing Technology, Chinese Academy of Sciences
P.O. Box 2704, Beijing 100190 P.R. China
E-mail: info@sjcjycl.cn
 
  Copyright ©2015 JCST, All Rights Reserved