【24h】

Toward Full Enterprise Software Support on nDPI

机译:在nDPI上获得全面的企业软件支持

获取原文

摘要

Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.
机译:下一代防火墙(NGFW)添加了标准防火墙的新功能,可以检查数据包内容,从而提高了准确性。 NGFW的三个主要用途是提高企业的服务质量(QoS),作为基于应用程序的筛选防火墙,并保护网络免受已知的安全威胁。完整的NGFW系统具有三个主要组件:深度包检查(DPI),入侵防御系统(IPS)和防火墙外智能机制。开源DPI实现的一个示例称为nDPI。随着企业应用程序(在商业组织中使用)的数量持续增加,nDPI在企业软件支持的覆盖范围方面也落后。这项研究的目的是在nDPI上设计和实现更好的企业级软件支持协议。选择并实施了五个常见的企业应用程序。然后,将实验结果与NGFW的商业实施方案进行比较,以整体精度和nDPI性能为依据。结果表明,新协议实现的nDPI的准确性达到90%以上,而CPU执行时间仅增加了很小的一部分(不到3.5%),峰值堆内存使用的增加了很小的一部分(不到1%)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号