- Article
39 Pages
Listed-Rule Firewalls (LRF) evaluate rules by first match: matching cost grows linearly with policy size, and ordered lists accumulate shadowing and redundancy anomalies. Tree-Rule Firewalls (TRF) match in a fixed number of levels, but their trees were built by hand; no procedure was known that turns an existing LRF policy into an equivalent tree. This paper presents an automated conversion whose correctness is proven end-to-end within a stated four-attribute IPv4 packet model. A four-dimensional range decomposition and a projection-normalization algorithm construct, from any LRF policy, a tree returning the same action for every packet; a deterministic O(n2) classifier first removes shadowed and redundant rules. A tree is fixed by a permutation of the four packet attributes; the framework admits the twelve permutations placing protocol before destination port. The tree’s decisions are invariant across these twelve orderings while its size is not: protocol-elsewhere orderings need 1.93× as many nodes as protocol-first orderings at 50 rules, matching time reaches statistical equivalence by 200 rules, and on a second policy sample the structural gap closes by 400 rules; the advantage is thus distribution-dependent. Across 73 million packet comparisons, no discrepancy from the original policy was observed; tree depth stayed at four on eight ClassBench-ng rulesets. All evaluated policies are synthetic or industry-calibrated synthetic and contain at most 400 rules.
Symmetry
24 September 2026


![Protocol-dependent dst_port domain. For TCP/UDP rules, dst_port is a 16-bit port number in [0, 65,535]. For ICMP rules, dst_port stores the ICMP type in [0, 255] (per RFC 792).](https://mdpi-res.com/cdn-cgi/image/width=470%2Cheight=317/https://mdpi-res.com/symmetry/symmetry-18-01596/article_deploy/html/images/symmetry-18-01596-g001-550.jpg)
![Energy of positive- and negative-parity states in the
Ca
40
nucleus as a function of J. The states identified with small green circles correspond to well-established spin–parity assignments, while the small red circles indicate states with uncertain spin–parity assignments. The brown lines connecting the circles represent electromagnetic transitions. All the states shown in the figure are taken from the compilation [59,60]. The black lines indicate rotational bands. In (a), the bands built on the 0+, 8+, and 3+ states, as well as the SD band, were previously proposed [9,59,60]. In (b), the 0− band was previously suggested [11,59,60]. The arranged bands are labeled according to the spin–parity (
J
π
) of their band head, with subscripts used to distinguish between bands with the same bandhead spin–parity.](https://mdpi-res.com/cdn-cgi/image/width=281%2Cheight=192/https://mdpi-res.com/symmetry/symmetry-18-01193/article_deploy/html/images/symmetry-18-01193-g001a-550.jpg)




