Firewall Wizards mailing list archives

Re: CERT vulnerability note VU# 539363 (fwd)


From: Carson Gaspar <carson () taltos org>
Date: Thu, 17 Oct 2002 16:35:19 -0400



--On Thursday, October 17, 2002 9:25 AM -0500 Stephen Gill <gillsr () yahoo com> wrote:

Hi Carson,
State entry lookups don't actually occur in constant time.

Yes they do, if you have enough memory, and a good enough hash function, such that collisions are low. The paper you mentioned argued that for the hash functions they tried, Khash > log(n)*Ktree, for reasonable values of n. It never said that the hash function time wasn't invariant with n.

--
Carson

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: