MARATTO

article

Optimizing Firewall Policy Rule Ordering Using Discrete Cuckoo Search Algorithm

Abstract

The exponential growth of modern network infrastructures has significantly increased the complexity of firewall configuration, often leading to rule conflicts and inefficient performance. Firewall rule ordering, a known NP-hard problem, is critical to ensuring accurate traffic filtering and preserving security policy semantics. Traditional deterministic approaches to packet classification often neglect traffic dynamics, limiting their adaptability. In this study, we propose a metaheuristic-based solution using the Discrete Cuckoo Search (DCS) algorithm to optimize firewall rule ordering. Inspired by natural behavior, DCS offers simplicity, global search capabilities, and computational efficiency. Our approach maps the rule ordering task to a job scheduling problem, achieving improved accuracy and performance compared to existing techniques. Experimental results validate the effectiveness of the proposed method in enhancing firewall efficiency.

Research topics

  • Network Packet Processing and Optimization
  • Network Traffic and Congestion Control
  • Software-Defined Networks and 5G

Sustainable Development Goals

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/wincom65874.2025.11313374

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.