Table 1.
Summary of evaluation on real-world firewalls
| Fw | Rules | Chain (unfolded) | Simple rules (no ifaces) | Use | Parts (ITVal) | SSH | HTTP | Time (ITVal) | Time (this) [s] |
|---|---|---|---|---|---|---|---|---|---|
| A | 2784 | FW (2376) | 2381 (1920) |
|
246 (1) | 13 | 9 | 3 | 172 |
| – | FW (2376) | 2837 (581) |
|
522 (1) | 1 | 1 | 9 | 194 | |
| A | 4113 | FW (2922) | 3114 (2862) |
|
334 (2) | 11 | 11 | 27 | 302 |
| – | FW (2922) | 3585 (517) |
|
490 (1) | 1 | 1 | 8 h | 320 | |
| A | 4814 | FW (4403) | 3574 (3144) |
|
364 (2) | 9 | 12 | 46 | 477 |
| – | FW (4403) | 5123 (1601) |
|
1574 (1) | 1 | 1 | 3 | 618 | |
| A | 4946 | FW (4887) | 4004 (3570) |
|
371 (2) | 9 | 12 | 53 | 578 |
| – | FW (4887) | 5563 (1613) |
|
1585 (1) | 1 | 1 | 4 | 820 | |
| B | 88 | FW (40) | 110 (106) |
|
50 (4) | 4 | 2 | 2 s | 3 |
| – | FW (40) | 183 (75) |
|
40 (1) | 1 | 1 | 1 s | 2 | |
| C | 53 | FW (30) | 29 (12) |
|
8 (1) | 1 | 1 | 1 s | 1 |
| – | FW (30) | 27 (1) |
|
1 (1) | 1 | 1 | 1 s | 1 | |
| – | IN (49) | 74 (46) |
|
38 (1) | 1 | 1 | 1 s | 1 | |
| – | IN (49) | 75 (21) |
|
6 (1) | 1 | 1 | 1 s | 1 | |
| D | 373 | FW (2649) | 3482 (166) |
|
43 (1) | 1 | 1 | 3 s | 22 |
| – | FW (2649) | 16592 (1918) |
|
67 (1) | 1 | 1 | 33 | 49 | |
| E | 31 | IN (24) | 57 (27) |
|
4 (3) | 1 | 2 | 1 s | 10 |
| – | IN (24) | 61 (45) |
|
3 (1) | 1 | 1 | 1 s | 1 | |
| F | 263 | IN (261) | 263 (263) |
|
250 (3) | 3 | 3 | 2 min | 80 |
| – | IN (261) | 265 (264) |
|
250 (3) | 3 | 3 | 3 min | 57 | |
| G | 68 | IN (28) | 20 (20) |
|
8 (5) | 1 | 2 | 1 s | 8 |
| – | IN (28) | 19 (19) |
|
8 (2) | 2 | 2 | 1 s | 1 | |
| H | 19 | FW (20) | 10 (10) |
|
9 (1) | 1 | 1 | 1 s | 8 |
| – | FW (20) | 8 (8) |
|
3 (1) | 1 | 1 | 1 s | 1 | |
| I | 15 | FW (5) | 4 (4) |
|
4 (4) | 4 | 4 | 1 s | 8 |
| – | FW (5) | 4 (4) |
|
4 (4) | 4 | 4 | 1 s | 1 | |
| J | 48 | FW (12) | 5 (5) |
|
3 (2) | 2 | 2 | 1 s | 6 |
| – | FW (12) | 8 (2) |
|
1 (1) | 1 | 1 | 1 s | 1 | |
| K | 21 | FW (9) | 7 (6) |
|
3 (1) | 1 | 1 | 1 s | 12 |
| – | FW (9) | 4 (3) |
|
2 (1) | 1 | 1 | 1 s | 1 | |
| L | 27 | IN (16) | 19 (19) |
|
17 (3) | 2 | 2 | 1 s | 1 |
| – | IN (16) | 18 (18) |
|
17 (3) | 2 | 2 | 1 s | 1 | |
| M | 80 | IN (92) | 64 (16) |
|
2 (2) | 1 | 2 | 1 s | 6 |
| – | IN (92) | 58 (27) |
|
11 (1) | 1 | 1 | 1 s | 1 | |
| N | 34 | FW (14) | 12 (12) |
|
10 (6) | 6 | 6 | 2 s | 2 |
| – | FW (14) | 12 (12) |
|
10 (6) | 6 | 6 | 2 s | 1 | |
| O | 8 | IN (7) | 9 (9) |
|
3 (3) | 1 | 2 | 1 s | 1 |
| – | IN (7) | 8 (8) |
|
3 (3) | 1 | 2 | 1 s | 1 | |
| P | 595 | IN (15) | 8 (8) |
|
3 (2) | 2 | 2 | 1 s | 6 |
| – | IN (15) | 9 (9) |
|
3 (2) | 2 | 2 | 1 s | 6 | |
| 595 | FW (66) | 64 (64) |
|
60 (5) | 5 | 4 | 22 s | 6 | |
| – | FW (66) | 63 (63) |
|
60 (5) | 5 | 4 | 22 s | 7 | |
| Q | 58 | IN (59) | 65 (65) |
|
21 (1) | 1 | 1 | 2 s | 2 |
| – | IN (59) | 62 (62) |
|
21 (2) | 2 | 1 | 2 s | 1 | |
| R | 30 | FW (28) | 123 (123) |
|
14 (1) | 1 | 6 | 1 s | 1 |
| – | FW (28) | 20 (3) |
|
2 (2) | 2 | 1 | 1 s | 1 |
ITVal memory consumption, in order of appearance: 84, 96, 94, 95, 61, 98, 96 and 21 GB