ABSTRACT
Firewalls, and packet classification in general, are becoming more and more significant as data rates soar and hackers become increasingly sophisticated - and more forceful. In this paper, we present a new packetclassification approach that uses set theory to classify packets. This approach has significant theoretical advantages over current approaches. We demonstrate its practicality by implementing a firewall subsystem in Linux which approaches the performance of today’s naive packet-filtering implementations.