- The document presents a new protocol for identifying redundant firewall rules across different administrative domains in a privacy-preserving manner.
- Prior work on firewall optimization focused only on intra-domain optimization where firewall policies could be shared. This presents the first approach for inter-domain optimization without disclosing private firewall policies.
- The key challenge is for two adjacent firewalls from different domains to identify redundant rules in each other's policies without revealing their actual policies. The proposed protocol uses compact predicates and firewall decision diagrams to detect redundant rules through cooperative computation while preserving privacy.