首页> 外文会议>2013 Fourth World Congress on Software Engineering >DPRP: Distributed Parallelled Rule Pre-matchings for NIDS: A Possible Way to Deploy Middlebox in Future Internet
【24h】

DPRP: Distributed Parallelled Rule Pre-matchings for NIDS: A Possible Way to Deploy Middlebox in Future Internet

机译:DPRP:NIDS的分布式并行规则预匹配:在将来的Internet中部署中间盒的可能方法

获取原文
获取原文并翻译 | 示例

摘要

Influenced by cloud computing and emerging software define network(SDN), today's Internet is changing. In this exciting background, how to deploy middle box functions is widely studied. Main trend is enterprise should outsourcing its middle box functionalities to third party, such as to public cloud[8] or to feather provider[7]. In this paper, we argue that we should not only study where to deploy the middle box functionalities, but also how to implement these functionalities more efficiently and scalable in future Internet. We propose DPRP, a distributed parallel rule pre-matching model for high performance and scalable NIDS implementation. The contribution of DPRP include: (1) DPRP separate hardware accelerator and software modules clearly, and use multiple parallel lightweight rule pre-matching units(RPU) to accelerate rule matching in NIDS. (2)RPU is reconfigurable. NIDS can add/remove RPUs dynamically according to rule matching demand, achieving better balance between performance and resource cost. (3)Hardware accelerators and software modules work in a distributed mode. It is scalable and accommodate to the control mode of the emerging SDN networks. We show the initial design results of RPU design and give more discussions about DPRP. As we know, this is the first work that proposes NIDS being implemented in distributed mode by decoupling hardware accelerators and software modules, which we think a possible way to deploy middle box in future Internet.
机译:受云计算和新兴软件定义网络(SDN)的影响,当今的Internet正在发生变化。在这种激动人心的背景下,如何部署中间盒功能得到了广泛的研究。主要趋势是企业应将其中间框功能外包给第三方,例如公共云[8]或羽毛供应商[7]。在本文中,我们认为,我们不仅应该研究中间盒功能的部署位置,而且还应该研究如何在未来的Internet中更有效和可扩展地实现这些功能。我们提出了DPRP,这是一种分布式并行规则预匹配模型,用于高性能和可扩展的NIDS实现。 DPRP的贡献包括:(1)DPRP清楚地将硬件加速器和软件模块分开,并使用多个并行的轻量级规则预匹配单元(RPU)来加速NIDS中的规则匹配。 (2)RPU是可重新配置的。 NIDS可以根据规则匹配需求动态添加/删除RPU,从而在性能和资源成本之间实现更好的平衡。 (3)硬件加速器和软件模块以分布式模式工作。它具有可扩展性,并适应新兴SDN网络的控制模式。我们将展示RPU设计的初步设计结果,并提供有关DPRP的更多讨论。众所周知,这是建议NIDS通过解耦硬件加速器和软件模块以分布式模式实现的第一项工作,我们认为这是在将来的Internet中部署中间盒的一种可能方式。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号