首页> 外文会议>2011 IEEE Students' Technology Symposium >Design and implementation of packet filter firewall using Binary Decision Diagram
【24h】

Design and implementation of packet filter firewall using Binary Decision Diagram

机译:基于二元决策图的包过滤防火墙的设计与实现

获取原文

摘要

Packet filtering is the one of the major contemporary firewall design techniques. An important design goal is to arrive at the decision at the packet only. Implementation of such packet filter using Binary Decision Diagram (BDD) gives more advantages in terms of memory usage and look up time. In the case of the list-based packet filter firewall where rules are checked one by one for each incoming packet, the time taken to decide on a packet is proportional to the number of rules. The performance is improved with rule promotion but that itself a slow procedure. In this work we present a BDD-based approach which gives much better result in terms of number of comparisons or accesses the rule list make. Results on 1 million packets show that for most-accept packets, on an average, 75% reduction happens in such comparisons when BDD-based approach is used over list-based with promotion approach. For most-reject packets this reduction is nearly 34%.
机译:数据包过滤是当代主要的防火墙设计技术之一。一个重要的设计目标是仅在数据包处做出决定。使用二进制决策图(BDD)来实现这种数据包筛选器在内存使用和查找时间方面具有更多优势。在基于列表的数据包筛选器防火墙的情况下,对每个传入数据包逐一检查规则,决定一个数据包所花费的时间与规则数量成正比。通过规则升级可以提高性能,但是这本身就是一个缓慢的过程。在这项工作中,我们提出了一种基于BDD的方法,该方法在比较次数或访问规则列表进行方面均提供了更好的结果。一百万个数据包的结果表明,对于大多数接受的数据包,当使用基于BDD的方法而不是基于列表的促销方法时,在这种比较中平均减少了75%。对于大多数被拒绝的数据包,这种减少将近34%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号