首页> 外文会议>IEEE International Conference on Communications >Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvement
【24h】

Multilevel early packet filtering technique based on traffic statistics and splay trees for firewall performance improvement

机译:基于交通统计和SPLAY树的多级早期数据包过滤技术,用于防火墙性能改进

获取原文

摘要

This paper presents a mechanism to improve firewall packet filtering time through optimizing the order of security policy filtering fields for early packet rejection. The proposed mechanism is based on the optimization of the filtering fields order according to traffic statistics. Furthermore, the mechanism uses multilevel packet filtering, and in each level unwanted packets are rejected as early as possible. So, the proposed mechanism can be considered also as a device protection mechanism against denial of service (DoS) attacks targeting the default policy rule. In addition, early packet acceptance is done through using the splay tree data structure which changes dynamically according to traffic flows. So, repeated packets will have less memory accesses and therefore reducing the overall packets matching time. The proposed technique aims to overcome some of the performance limitations of the previous technique, named Self Adjusting Binary Search on Prefix Length [1] (SA-BSPL). The numerical results obtained by simulations demonstrate that the proposed mechanism is able to significantly improve the firewall performance in terms of cumulative packet processing time compared to SA-BSPL technique.
机译:本文通过优化早期数据包抑制的安全策略过滤字段的顺序来提高防火墙分组过滤时间的机制。该机制根据交通统计数据提供了过滤字段的优化。此外,该机制使用多级分组滤波,并且在每个级别中尽早被不需要的分组拒绝。因此,所提出的机制也可以被认为是针对拒绝服务(DOS)攻击的设备保护机制,该机制针对默认策略规则。此外,通过使用根据业务流动态地改变的SPLAY TREE DEAT数据结构来完成早期的数据包接受。因此,重复数据包将具有较少的内存访问,因此减少了匹配时间的整体数据包。所提出的技术旨在克服先前技术的一些性能限制,命名为自我调整二进制搜索的前缀长度[1](SA-BSPL)。通过模拟获得的数值结果表明,与SA-BSPL技术相比,所提出的机制能够在累积分组处理时间方面显着改善防火墙性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号