<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root>
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" dtd-version="1.2" xml:lang="en"><front><journal-meta><journal-id journal-id-type="publisher-id">Discrete and Continuous Models and Applied Computational Science</journal-id><journal-title-group><journal-title xml:lang="en">Discrete and Continuous Models and Applied Computational Science</journal-title><trans-title-group xml:lang="ru"><trans-title>Discrete and Continuous Models and Applied Computational Science</trans-title></trans-title-group></journal-title-group><issn publication-format="print">2658-4670</issn><issn publication-format="electronic">2658-7149</issn><publisher><publisher-name xml:lang="en">Peoples' Friendship University of Russia named after Patrice Lumumba (RUDN University)</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">37515</article-id><article-id pub-id-type="doi">10.22363/2658-4670-2023-31-4-345-358</article-id><article-id pub-id-type="edn">DYDLCY</article-id><article-categories><subj-group subj-group-type="toc-heading" xml:lang="en"><subject>Articles</subject></subj-group><subj-group subj-group-type="toc-heading" xml:lang="ru"><subject>Статьи</subject></subj-group><subj-group subj-group-type="article-type"><subject>Research Article</subject></subj-group></article-categories><title-group><article-title xml:lang="en">Evaluation of firewall performance metrics with ranging the rules for Poisson incoming packet flow and exponential filtering time</article-title><trans-title-group xml:lang="ru"><trans-title>Оценка показателей эффективности межсетевого экрана с ранжированием правил для пуассоновского входящего потока пакетов и экспоненциального времени фильтрации</trans-title></trans-title-group></title-group><contrib-group><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0003-1412-981X</contrib-id><name-alternatives><name xml:lang="en"><surname>Botvinko</surname><given-names>Anatoly Yu.</given-names></name><name xml:lang="ru"><surname>Ботвинко</surname><given-names>А. Ю.</given-names></name></name-alternatives><bio xml:lang="en"><p>Candidate of Physical and Mathematical Sciences, assistant professor of Department of Probability Theory and Cyber Security</p></bio><email>botvinko_ayu@rudn.ru</email><xref ref-type="aff" rid="aff1"/></contrib><contrib contrib-type="author"><contrib-id contrib-id-type="orcid">https://orcid.org/0000-0002-6368-9680</contrib-id><name-alternatives><name xml:lang="en"><surname>Samouylov</surname><given-names>Konstantin E.</given-names></name><name xml:lang="ru"><surname>Самуйлов</surname><given-names>К. Е.</given-names></name></name-alternatives><bio xml:lang="en"><p>Professor, Doctor of Technical Sciences, Head of the Department of Probability Theory and Cyber Security</p></bio><email>samuylov_ke@rudn.ru</email><xref ref-type="aff" rid="aff1"/></contrib></contrib-group><aff-alternatives id="aff1"><aff><institution xml:lang="en">RUDN University</institution></aff><aff><institution xml:lang="ru">Российский университет дружбы народов</institution></aff></aff-alternatives><pub-date date-type="pub" iso-8601-date="2023-12-15" publication-format="electronic"><day>15</day><month>12</month><year>2023</year></pub-date><volume>31</volume><issue>4</issue><issue-title xml:lang="en">VOL 31, NO4 (2023)</issue-title><issue-title xml:lang="ru">ТОМ 31, №4 (2023)</issue-title><fpage>345</fpage><lpage>358</lpage><history><date date-type="received" iso-8601-date="2024-01-19"><day>19</day><month>01</month><year>2024</year></date></history><permissions><copyright-statement xml:lang="en">Copyright ©; 2023, Botvinko A.Y., Samouylov K.E.</copyright-statement><copyright-statement xml:lang="ru">Copyright ©; 2023, Ботвинко А.Ю., Самуйлов К.Е.</copyright-statement><copyright-year>2023</copyright-year><copyright-holder xml:lang="en">Botvinko A.Y., Samouylov K.E.</copyright-holder><copyright-holder xml:lang="ru">Ботвинко А.Ю., Самуйлов К.Е.</copyright-holder><ali:free_to_read xmlns:ali="http://www.niso.org/schemas/ali/1.0/"/><license><ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/">https://creativecommons.org/licenses/by-nc/4.0</ali:license_ref></license></permissions><self-uri xlink:href="https://journals.rudn.ru/miph/article/view/37515">https://journals.rudn.ru/miph/article/view/37515</self-uri><abstract xml:lang="en"><p style="text-align: justify;">The given article is a continuation of a number of works devoted to the development of models and methods for ranging the filtration rules to prevent a decrease in the firewall performance caused by the use of a sequential scheme for checking packet compliance with the rules, as well as by the heterogeneity and variability of network traffic. The article includes a description of a firewall mathematical model given in the form of a complex system and a queuing system with a phase-type discipline for request servicing, which formalizes the network traffic filtering process with the functionality of ranging the rules. The purpose of modeling is to obtain estimates for major firewall performance metrics for various network traffic behavior scenarios, as well as to evaluate an increase in the firewall performance due to ranging a filtration rule set. Calculation of estimates for the firewall (FW) performance metrics was made using the analytical method for a Poisson request flow. Based on the analysis of the modeling results, conclusions were drawn on the effectiveness of ranging the filtration rules in order to improve the firewall performance for traffic scenarios that are close to real ones.</p></abstract><trans-abstract xml:lang="ru"><p style="text-align: justify;">Данная статья является развитием ряда работ по разработке моделей и методов ранжирования правил фильтрации для предотвращения снижения производительности межсетевого экрана, обусловленной использованием последовательной схемы проверки соответствия пакетов правилам, неоднородностью и изменчивостью сетевого трафика. В статье приведено описание математической модели межсетевого экрана в виде сложной системы и системы массового обслуживания с дисциплиной обслуживания заявок фазового типа, формализующей процесс фильтрации сетевого трафика с функциональной возможностью ранжирования правил. Целью моделирования является получение оценок основных показателей эффективности межсетевого экрана для различных сценариев поведения сетевого трафика, а также оценка повышения производительности за счёт ранжирования набора правил фильтрации. Вычисление оценок показателей эффективности МЭ проводится аналитическим способом для пуассоновского потока заявок. На основании анализа результатов моделирования сделаны выводы об эффективности ранжирования правил фильтрации для повышения производительности межсетевых экранов для сценариев трафика, близких к реальным.</p></trans-abstract><kwd-group xml:lang="en"><kwd>firewall</kwd><kwd>ranging the filtration rules</kwd><kwd>network traffic</kwd><kwd>phase service</kwd><kwd>queuing system</kwd></kwd-group><kwd-group xml:lang="ru"><kwd>межсетевой экран</kwd><kwd>ранжирование правил фильтрации</kwd><kwd>сетевой трафик</kwd><kwd>фазовое обслуживание</kwd><kwd>система массового обслуживания</kwd></kwd-group><funding-group><funding-statement xml:lang="en">This paper has been supported by the RUDN University Strategic Academic Leadership Program.</funding-statement></funding-group></article-meta></front><body></body><back><ref-list><ref id="B1"><label>1.</label><mixed-citation>A. Y. Botvinko and K. E. Samouylov, “Evaluation of firewall performance when ranging a filtration rule set,” Discrete and Continuous Models and Applied Computational Science, vol. 29, no. 3, pp. 230-241, 2013. DOI: 10.22363/2658-4670-2021-29-3-230-241.</mixed-citation></ref><ref id="B2"><label>2.</label><mixed-citation>A. Y. Botvinko and K. E. Samouylov, “Firewall simulator development for performance evaluation of ranging a filtration rules set,” Distributed Computer and Communication Networks: Control, Computation, Communications. DCCN 2022. Lecture Notes in Computer Science. Lecture Notes in Computer Science, vol. 13766, no. 3, pp. 221-229, 2022. DOI: 10.1007/978-3-031-23207-7_15.</mixed-citation></ref><ref id="B3"><label>3.</label><mixed-citation>A. Y. Botvinko and K. E. Samouylov, “Firewall simulation model with filtering rules ranking,” Distributed Computer and Communication Networks: Control, Computation, Communications. DCCN 2020. Communications in Computer and Information Science, vol. 1337, pp. 533- 545, 2020. DOI: 10.1007/978-3-030-66242-4_42.</mixed-citation></ref><ref id="B4"><label>4.</label><mixed-citation>V. Katkovnik, Non-parametric data identification and smoothing: local approximation method [Neparametricheskaya identifikaciya i sglazhivanie danny‘x: metod lokal‘noj approksimacii]. The science. Main editorial office of physical and mathematical literature Publ., 1985, 336 pp., in Russian.</mixed-citation></ref><ref id="B5"><label>5.</label><mixed-citation>W. Hardle, Applied nonparametric regression. Cambridge: Cambridge university press, 1990, 349 pp.</mixed-citation></ref><ref id="B6"><label>6.</label><mixed-citation>M. Cheminod, L. Durante, L. Seno, and A. Valenzano, “Performance evaluation and modeling of an industrial application-layer firewall,” IEEE Transactions on Industrial Informatics, vol. 14, no. 5, pp. 2159- 2170, 2018. DOI: 10.1109/TII.2018.2802903.</mixed-citation></ref><ref id="B7"><label>7.</label><mixed-citation>K. Salah, K. Elbadawi, and R. Boutaba, “Performance modeling and analysis of network firewalls,” IEEE Transactions on network and service management, vol. 9, no. 1, pp. 12-21, 2011. DOI: 10.1109/TNSM.2011.122011.110151.</mixed-citation></ref><ref id="B8"><label>8.</label><mixed-citation>P. P. Bocharov and A. V. Pechenkin, Queuing theory [Teoriya massovogo obsluzhivaniya]. Moscow: RUDN, 1995, 529 pp., in Russian.</mixed-citation></ref></ref-list></back></article>
