Research Article

Adaptive Conflict-Free Optimization of Rule Sets for Network Security Packet Filtering Devices

Table 1

Percentage improvement (PI) of the efficiency parameter due to ACO rule extraction and optimization as a function of attacking flow packet rate, for TCP, UDP, and FTP legitimate flows.

  pkts/s TCP PI % UDP PI % FTP PI %

3124 0.04 0.00
6553 0.00 0.03 50.00
9830 27.29 0.47 50.00
13107 17.84 1.96 40.49
15626 20.93 3.61 66.67
31247 12.02 5.50 64.37
47576 26.58 17.55 72.79
62429 33.73 34.71 104.02
83092 21.87 32.92 64.51
99730 22.16 22.00 65.81
110655 20.61 23.65 64.71
131072 21.47 26.88 63.34
196608 18.83 26.59 68.42
262144 18.92 27.20 64.93