Enabling security over internet, firewalls play a major
role. It checks all incoming or outgoing packet to decide whether
to accept or discard the packet based on its policy. Firewall
optimization focuses on either intra-firewall or inter-firewall
optimization within one administrative domain where the
privacy of firewall policies is not a concern. Explore Interfirewall
optimization across administrative domains for the first time.
The key technical challenge is that firewall policies cannot be
shared across domains because a firewall policy contains
confidential information and even potential security holes, which
can be exploited by attackers. Using Interfirewall redundant rule
which overcome the prior problem and enable the Interfirewall
optimization across administrative domains. Also propose the
first cross-domain cooperative firewall (CDCF) policy
optimization protocol. The optimization process involves
cooperative computation between the two firewalls without any
party disclosing its policy to the other. We implemented our
protocol in Java and conducted extensive evaluation.