...
首页> 外文期刊>Computer communication review >Securing Linux with a Faster and Scalable IPtables
【24h】

Securing Linux with a Faster and Scalable IPtables

机译:使用更快和可扩展的IPtable保护Linux安全

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

The sheer increase in network speed and the massive deployment of containerized applications in a Linux server has led to the consciousness that iptables, the current de-facto firewall in Linux, may not be able to cope with the current requirements particularly in terms of scalability in the number of rules. This paper presents an eBPF-based firewall, bpf-iptables, which emulates the iptables filtering semantic while guaranteeing higher throughput. We compare our implementation against the current version of iptables and other Linux firewalls, showing how it achieves a notable boost in terms of performance particularly when a high number of rules is involved. This result is achieved without requiring custom kernels or additional software frameworks (e.g., DPDK) that could not be allowed in some scenarios such as public data-centers.
机译:网络速度的飞速增长和Linux服务器中容器化应用程序的大规模部署已经引起人们的意识,即iptables(Linux中当前的事实上的防火墙)可能无法满足当前的需求,尤其是在扩展性方面。规则数量。本文提出了一种基于eBPF的防火墙bpf-iptables,该防火墙模仿了iptables过滤语义,同时保证了更高的吞吐量。我们将实现与当前版本的iptables和其他Linux防火墙进行了比较,展示了它如何在性能方面取得显着提升,尤其是在涉及大量规则时。无需在某些情况下(例如公共数据中心)不允许使用的自定义内核或其他软件框架(例如DPDK),就可以实现此结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号