首页> 外文会议>2012 IEEE International Conference on Communications. >Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvement
【24h】

Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvement

机译:基于流量统计和展开树的多层早期数据包过滤技术可提高防火墙性能

获取原文
获取原文并翻译 | 示例

摘要

This paper presents a mechanism to improve firewall packet filtering time through optimizing the order of security policy filtering fields for early packet rejection. The proposed mechanism is based on the optimization of the filtering fields order according to traffic statistics. Furthermore, the mechanism uses multilevel packet filtering, and in each level unwanted packets are rejected as early as possible. So, the proposed mechanism can be considered also as a device protection mechanism against denial of service (DoS) attacks targeting the default policy rule. In addition, early packet acceptance is done through using the splay tree data structure which changes dynamically according to traffic flows. So, repeated packets will have less memory accesses and therefore reducing the overall packets matching time. The proposed technique aims to overcome some of the performance limitations of the previous technique, named Self Adjusting Binary Search on Prefix Length [1] (SA-BSPL). The numerical results obtained by simulations demonstrate that the proposed mechanism is able to significantly improve the firewall performance in terms of cumulative packet processing time compared to SA-BSPL technique.
机译:本文提出了一种机制,该机制可通过优化安全策略过滤字段的顺序以缩短早期数据包拒绝时间来缩短防火墙数据包过滤时间。所提出的机制是基于根据流量统计信息优化过滤字段顺序的。此外,该机制使用多级数据包过滤,并且在每个级别中,不希望有的数据包都将尽早被拒绝。因此,提出的机制也可以视为针对默认策略规则的针对拒绝服务(DoS)攻击的设备保护机制。另外,通过使用随业务流量动态变化的扩展树数据结构,可以实现早期的数据包接受。因此,重复的数据包将具有较少的内存访问,因此减少了总的数据包匹配时间。所提出的技术旨在克服先前技术的一些性能限制,该技术称为前缀长度[1](SA-BSPL)的自调整二进制搜索。通过仿真获得的数值结果表明,与SA-BSPL技术相比,该机制在累积数据包处理时间方面能够显着提高防火墙性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号