Purpose – This study proposes a formally specified, composable extension of RFC 9411 for benchmarking sandbox-based advanced threat prevention (ATP) in next-generation firewalls (NGFWs). It addresses four properties that the current standard cannot characterize: asynchronous verdict generation, file-level inspection granularity, bypass behavior under overload, and verdict latency as a security efficacy dimension.Methods – Following a design science methodology, the study develops a framework comprising a test traffic profile parameterized by file arrival rate (F), size distribution (s), type distribution (t), and maliciousness ratio (m); five formally defined key performance indicators (KPIs); a mapping table relating each component to its RFC 9411 counterpart; and a three-phase test procedure covering steady-state, overload, and recovery conditions. Empirical need is established through a vendor disclosure survey across three leading enterprise NGFW product lines.Findings – An illustrative scenario application, using plausible values rather than instrumented measurements, shows how the proposed KPIs would expose behaviors invisible to RFC 9411, such as a policy-driven bypass of 14% under a 30% traffic overload and a quantifiable trade-off between detection rate (α = 0.91–0.96) and verdict latency (p50 = 18–47 s). Empirically, a disclosure survey of three enterprise NGFW datasheets finds all five sandbox-specific KPIs absent from every datasheet, with composite disclosure indices of 23–34% and a cross-vendor mean of 28%. Research implications – The framework enables reproducible, comparable sandbox benchmarking and provides a normative basis for SLA design, evidence-based procurement, and IETF BMWG standardization.Originality – This study contributes the first formally specified, RFC 9411-composable benchmarking layer for sandbox-based ATP, introducing five new KPIs with mathematical definitions and a composability mapping table.
Copyrights © 2026