首页> 外文期刊>Networking, IEEE/ACM Transactions on >A Difference Resolution Approach to Compressing Access Control Lists
【24h】

A Difference Resolution Approach to Compressing Access Control Lists

机译:差异解决方案压缩访问控制列表

获取原文
获取原文并翻译 | 示例

摘要

Access control lists (ACLs) are the core of many networking and security devices. As new threats and vulnerabilities emerge, ACLs on routers and firewalls are getting larger. Therefore, compressing ACLs is an important problem. In this paper, we propose a new approach, called Diplomat, to ACL compression. The key idea is to transform higher dimensional target patterns into lower dimensional patterns by dividing the original pattern into a series of hyperplanes and then resolving differences between two adjacent hyperplanes by adding rules that specify the differences. This approach is fundamentally different from prior ACL compression algorithms and is shown to be very effective. We implemented Diplomat and conducted side-by-side comparison with the prior Firewall Compressor, TCAM Razor, and ACL Compressor algorithms on real life classifiers. Our experimental results show that Diplomat outperforms all of them on most of our real-life classifiers, often by a considerable margin, particularly as classifier size and complexity increases. In particular, on our largest ACLs, Diplomat has an average improvement ratio of 34.9% over Firewall Compressor on range-ACLs, of 14.1% over TCAM Razor on prefix-ACLs, and 8.9% over ACL Compressor on mixed-ACLs.
机译:访问控制列表(ACL)是许多网络和安全设备的核心。随着新的威胁和漏洞的出现,路由器和防火墙上的ACL越来越大。因此,压缩ACL是一个重要的问题。在本文中,我们提出了一种称为Diplomat的ACL压缩新方法。关键思想是通过将原始模式划分为一系列超平面,然后通过添加指定差异的规则来解决两个相邻超平面之间的差异,从而将高维目标图案转换为低维图案。这种方法从根本上不同于现有的ACL压缩算法,并且被证明是非常有效的。我们实现了Diplomat,并与现实生活中的分类器上的以前的Firewall Compressor,TCAM Razor和ACL Compressor算法进行了并排比较。我们的实验结果表明,在大多数现实生活中的分类器中,Diplomat的性能均优于所有分类器,尤其是随着分类器的尺寸和复杂性的增加,其表现通常都相当可观。特别是,在我们最大的ACL上,Diplomat在范围ACL上比Firewall Compressor平均提高34.9%,在前缀ACL上比TCAM Razor高14.1%,在混合ACL上比ACL Compressor高8.9%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号