unreachable rules are shadowed by default. The
respective checks for these rules can be skipped.
This is also true for initial rules which are always
reachable and unshadowed.
• Parallelization - The overall performance can be
improved by parallelizing parts of the application.
Especially, the building and solving of unreacha-
bility and shadowing formulas is completely in-
dependent and can be processed in parallel. Also,
parts of the building process may be parallelized
as well.
• Expressiveness - There are further interesting fea-
tures for the policy anomaly detection like the
support for stateful firewalling or the considera-
tion of effects introduced by VPN-tunnels.
