A Simple Mathematical Model for Policies, Rules, and Packets
At this point it is perhaps useful to describe firewall policies, firewall rules, and network
packets using set theory [1]. The previous section defined the parts and fields of rules and
packets as tuples. A tuple can be modeled as a set. For example, assume the tuple for IP
source addresses is 198.188.150.*. Then this tuple represents the set of 256 addresses that