Abstract
Packet classification is a central function in firewalls, intrusion detection mechanisms and monitoring architectures. Network elements assuming these techniques operate on packet flows to insure access control. A large variety of multi-fields packet classification techniques were reported in litterature but it remains difficult to find a packet classification solution that represents a good tradeoff between classification times, fast updates, memory requirements and scalability to large filters database. In this paper, we introduce a new five-fields classification concept, the two level classification algorithms based on an architecture that can be applied to any decision treebased packet classification algorithm, we test it with a well-known algorithm the Extended Grid-of-Tries and present performance measurments. In this paper, we show how our algorithm improves search times.