Enhanced Session Table Architecture for Stateful Firewalls
Zouheir Trabelsi, Safaa Zeidan · 2018
Stateful firewall keeps track of the state of network connections. The performance of stateful firewall determines by both the performance of its session table and the mechanism used for packet filtering. This paper presents a stateful session table architecture then integrates it with Splay tree firewall. Splay tree firewall organizes policy rules in a designated prefix length splay tree data structure, and a collection of hash tables grouped by prefix length. Packet filtering time using Splay tree firewall is essentially reduced through multilevel filtering paths, where unwanted packets are rejected as early as possible. The proposed session table architecture reduces memory space consumption and session operations time, as it uses one hash slot per connection. Keeping all connection related information in one session entry produces additional processing time, particularly for session timeout attribute processing. Our proposed session architecture separates session state and timeout attributes information into different data structures to enhance the overall system performance.