首页> 外文会议>ACM workshop on Storage security and survivability >Design, implementation and evaluation of security in iSCSI-based network storage systems
【24h】

Design, implementation and evaluation of security in iSCSI-based network storage systems

机译:基于iSCSI的网络存储系统的设计,实现和安全性评估

获取原文

摘要

This paper studies the performance and security aspects of the iSCSI protocol in a network storage based system. Ethernet speeds have been improving rapidly and network throughput is no longer considered a bottleneck when compared to Fibre-channel based storage area networks. However, when security of the data traffic is taken into consideration, existing protocols like IPSec prove to be a major hindrance to the overall throughput. In this paper, we evaluate the performance of iSCSI when deployed over standard security protocols and suggest lazy crypto approaches to alleviate the processing needs at the server. The testbed consists of a cluster of Linux machines directly connected to the server through a Gigabit Ethernet network. Micro and application benchmarks like BTIO and dbench were used to analyze the performance and scalability of the different approaches. Our proposed lazy approaches improved through-put by as much as 46% for microbenchmarks and 30% for application benchmarks in comparisonto the IPSec based approaches.
机译:本文研究了基于网络存储的系统中iSCSI协议的性能和安全性方面。与基于光纤通道的存储区域网络相比,以太网速度一直在迅速提高,并且网络吞吐量不再被视为瓶颈。但是,当考虑到数据流量的安全性时,像IPSec这样的现有协议被证明是总体吞吐量的主要障碍。在本文中,我们评估了在标准安全协议上部署时iSCSI的性能,并建议采用惰性加密方法来减轻服务器的处理需求。该测试平台由一簇Linux计算机组成,这些Linux计算机通过千兆以太网直接连接到服务器。微型和应用程序基准测试(例如BTIO和dbench)用于分析不同方法的性能和可伸缩性。与基于IPSec的方法相比,我们提出的惰性方法将微基准的吞吐量提高了46%,将应用程序基准的吞吐量提高了30%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号