Architecture of Protection: Comparing Stateless and Stateful Firewall Rules with CS Unplugged

Authors

DOI:

https://doi.org/10.17509/jatikom.v9i1.884

Keywords:

Firewall Architecture; Stateless vs Stateful; CS Unplugged; Network Security; Pedagogical Approach

Abstract

Firewalls are essential components in computer networks, designed to protect against external threats and regulate data traffic. Furthermore, the increasing prevalence of web-based threats, such as Cross-Site Scripting (XSS) and SQL Injection, highlights the critical need for robust security measures and a deeper understanding of how traffic filtering operates at different network layers. There are two main firewall architectures: stateless and stateful, each with distinct characteristics and advantages. This study aims to compare these architectures through an educational approach utilizing CS Unplugged activities, which incorporate physical and collaborative exercises to understand firewall mechanisms. The research employs a mixed-method approach involving 60 undergraduate students, combining quantitative pre-test and post-test analysis with qualitative thematic analysis. Results indicate a significant improvement in students’ comprehension of both network protection paradigms. Specifically, students' understanding of stateless rule logic demonstrated the highest gain, increasing from 33% in the pre-test to 96% in the post-test. Additionally, qualitative data shows that CS Unplugged activities facilitate the construction of mental models, helping students grasp complex packet processing and session control processes. Despite these positive outcomes, this pedagogical approach has limitations regarding scalability in representing large-scale enterprise rules and the inability to manually model AI-enabled dynamic rule optimization or deep packet inspection. Therefore, future research is recommended to explore a hybrid approach that integrates these foundational unplugged activities with subsequent digital simulator-based labs to bridge the gap between conceptual understanding and operational proficiency. Ultimately, these findings support active learning strategies in cybersecurity education, offering an effective means to enhance conceptual understanding and reduce common configuration misconceptions. 

Author Biographies

  • Agung Arya Anggara, Indonesia University of Education

    Agung Arya Anggara is an Student in the Department of Computer Science Education at Universitas Pendidikan Indonesia, Bandung, Indonesia.

  • Jajang Kusnendar, Indonesia University of Education

    Jajang Kusnendar is a Lecturer in the Department of Computer Science Education at Universitas Pendidikan Indonesia, Bandung, Indonesia.

  • Perdiansah, Indonesia University of Education

    Perdiansah is an Student in the Department of Computer Science Education at Universitas Pendidikan Indonesia, Bandung, Indonesia.

  • Muhammad Huda Zanatul Mak’wa, Indonesia University of Education

    Muhammad Huda Zanatul Mak’wa is an Undergraduate Student in the Department of Computer Science Education at Universitas Pendidikan Indonesia, Bandung, Indonesia.

Downloads

Published

2026-08-11

Issue

Section

Articles

How to Cite

Architecture of Protection: Comparing Stateless and Stateful Firewall Rules with CS Unplugged. (2026). Jurnal Aplikasi Dan Teori Ilmu Komputer, 9(1), 36-43. https://doi.org/10.17509/jatikom.v9i1.884