Parallelization of IP-packet filter rules

Takeshi Miei, M. Maruyama, T. Ogura, Naoshi Takahashi · 2002

A compiler for parallelizing IP-packet filter rules is presented which will improve network security and reduce packet-forwarding performance degradation. It analyzes the interdependence of packet-filtering rules specified by a network administrator and translates them into an intermediate program whose instructions can be executed in parallel. Three types of compiler operations are introduced: division is used to divide the rules into parallel expressions, simplification is used to simplify redundant rules, deletion is used to delete infeasible rules.

Read the paper · More papers on PaperTik