首页> 外文会议>IEEE Students' Technology Symposium >Design and implementation of packet filter firewall using Binary Decision Diagram
【24h】

Design and implementation of packet filter firewall using Binary Decision Diagram

机译:使用二进制决策图的数据包过滤器防火墙的设计与实现

获取原文

摘要

Packet filtering is the one of the major contemporary firewall design techniques. An important design goal is to arrive at the decision at the packet only. Implementation of such packet filter using Binary Decision Diagram (BDD) gives more advantages in terms of memory usage and look up time. In the case of the list-based packet filter firewall where rules are checked one by one for each incoming packet, the time taken to decide on a packet is proportional to the number of rules. The performance is improved with rule promotion but that itself a slow procedure. In this work we present a BDD-based approach which gives much better result in terms of number of comparisons or accesses the rule list make. Results on 1 million packets show that for most-accept packets, on an average, 75% reduction happens in such comparisons when BDD-based approach is used over list-based with promotion approach. For most-reject packets this reduction is nearly 34%.
机译:数据包过滤是主要的当代防火墙设计技术之一。 重要的设计目标是仅在数据包的决定中到达。 使用二进制决策图(BDD)实现此类分组滤波器在内存使用方面提供了更多优势,并查找时间。 在基于列表的分组过滤器防火墙的情况下,对于每个传入分组,将逐个选中规则,以对数据包决定的时间与规则的数量成比例。 该性能随着规则推广而得到改善,但本身是一种缓慢的程序。 在这项工作中,我们提出了一种基于BDD的方法,它就比较数量提供了更好的结果,或者访问规则列表制作。 结果100万数据包显示,对于大多数接受数据包,平均而言,在基于BDD的方法与促销方法的基于名单上使用时,这种比较会发生75%。 对于大多数拒绝数据包,这种减少近34%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号