首页> 外文期刊>Computer networks >Modeling and performance evaluation of transport protocols for firewall control
【24h】

Modeling and performance evaluation of transport protocols for firewall control

机译:防火墙控制传输协议的建模和性能评估

获取原文
获取原文并翻译 | 示例

摘要

Firewalls are a crucial building block for securing IP networks. The usage of out-of-band signaling protocols such as SIP for IP telephony and multimedia applications requires a dynamic control of these firewalls and imposes several challenges. Recently, several firewall control architectures and protocols have been developed. The main focus of this paper is the simple middlebox configuration protocol (SIMCO), which is a new transaction-based firewall control protocol. Due to the impact on call setup delays, firewall signaling requires small end-to-end delays and thus mandates a careful choice of the transport protocol. Therefore, this paper studies SCTP, TCP and UDP-based transport for SIMCO and compares different configurations that allow to optimize the performance. We present an analytical model to quantify the impact of head-of-line blocking in SCTP and TCP and verify it with measurements. Both the model and measurements reveal that SCTP can significantly reduce the SIMCO response times by leveraging transmission over multiple parallel streams. While already a few SCTP streams can almost completely avoid head-of-line blocking, our results show that TCP- and UDP-based transport may suffer from significantly larger delays.
机译:防火墙是保护IP网络安全的重要组成部分。对于IP电话和多媒体应用程序使用带外信令协议(例如SIP)要求对这些防火墙进行动态控制,并带来一些挑战。最近,已经开发了几种防火墙控制体系结构和协议。本文的主要重点是简单的中间盒配置协议(SIMCO),它是一种新的基于事务的防火墙控制协议。由于对呼叫建立延迟的影响,防火墙信令需要较小的端到端延迟,因此需要谨慎选择传输协议。因此,本文研究了SIMCO基于SCTP,TCP和UDP的传输,并比较了允许优化性能的不同配置。我们提出了一个分析模型,以量化对SCTP和TCP中的行头阻塞的影响,并通过测量进行验证。模型和测量结果均表明,SCTP可通过利用多个并行流上的传输来显着减少SIMCO响应时间。尽管已经有一些SCTP流几乎可以完全避免行首阻塞,但我们的结果表明,基于TCP和UDP的传输可能会遭受明显更大的延迟。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号