Multi-dimension rule update in a TCAM-based high-performance network security system

被引:0
|
作者
Jeong, Hae-Jin [1 ]
Song, Il-Seop [1 ]
Lee, Yoo-Kyoung [2 ]
Kwon, Taeck-Geun [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci & Engn, 220 Gung Dong, Taejon 305764, South Korea
[2] Elect & Telecommun Res Inst, Taejon 305701, South Korea
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network security systems such as firewall and intrusion prevention system (IPS) have packet classification rule to allow or protect the network traffic. In addition, they are forced to provide multi-gigabit speed in order to deploy the current Internet backbone which requires gigabit Ethernet (GbE), 10 GbE, OC-192, etc. in order to support high-performance packet classification in the network security system, a Ternary Content Addressable Memory, i.e., TCAM accelerates flow identification with classification rules. The TCAM, however, matches the first rule among multiple matched rules, so the ordering of TCAM entries is strictly kept while rules are added or deleted. To keep the ordering in a TCAM, some existing TCAM entries should move to other empty space which impacts the data path processing in the network security system. In this paper, we have proposed a rule update algorithm which reduces the number of TCAM entry movement by the partial ordering of TCAM entry groups instead of the sequential ordering. Our simulation results justify the significant decrement of movement operations where we have applied both generated random rules and real IPS rules, i.e., Snort rules.
引用
收藏
页码:62 / +
页数:2
相关论文
共 50 条
  • [1] A high-performance multi-match priority encoder for TCAM-based packet classifiers
    Faiezipour, Miad
    Nourani, Mehrdad
    2007 IEEE DALLAS/CAS WORKSHOP ON SYSTEM-ON-CHIP (SOC): DESIGN, APPLICATIONS, INTEGRATION, AND SOFTWARE, 2007, : 85 - +
  • [2] RuleTris: Minimizing Rule Update Latency for TCAM-based SDN Switches
    Wen, Xitao
    Yang, Bo
    Chen, Yan
    Li, Li Erran
    Bu, Kai
    Zheng, Peng
    Yang, Yang
    Hu, Chengchen
    PROCEEDINGS 2016 IEEE 36TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS ICDCS 2016, 2016, : 179 - 188
  • [3] Pipelined Implementation of TCAM-Based Search Engines in High-Performance IP Routers
    Yu, Hui
    Chen, Jing
    Wang, Jianping
    Zheng, S. Q.
    GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, 2008,
  • [4] PPLTCAM: A parallel TCAM-based IP address lookup structure with high incremental update performance
    Wang, Fei
    Hong, Yi
    Xu, Cong
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2019, 31 (10):
  • [5] Multi-Dimension Threat Situation Assessment Based on Network Security Attributes
    Yu, Yang
    Wang, Jian
    Liu, Jiqiang
    Han, Lei
    He, Xudong
    Lv, Shaohua
    2018 27TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND NETWORKS (ICCCN), 2018,
  • [6] TCAM-Based Multi-Match Packet Classification Using Multidimensional Rule Layering
    Chang, Dao-Yuan
    Wang, Pi-Chung
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2016, 24 (02) : 1125 - 1138
  • [7] D-TCAM: A High-Performance Distributed RAM Based TCAM Architecture on FPGAs
    Irfan, Muhammad
    Ullah, Zahid
    Cheung, Ray C. C.
    IEEE ACCESS, 2019, 7 : 96060 - 96069
  • [8] A Security Strategy Based on Multi-Dimension Location for Hierarchical Wireless Heterogeneous Sensor Networks
    Zhang, Yuquan
    Wei, Lei
    PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 625 - 630
  • [9] H/W based Firewall for high-performance network security
    Ko, JG
    Kim, KY
    Ryu, KW
    Certification and Security in Inter-Organizational E-Services, 2005, 177 : 141 - 149
  • [10] Zodiac: System Architecture Implementation for a High-Performance Network Security Processor
    Wang Haixin
    Bai Guoqiang
    Chen Hongyi
    2008 INTERNATIONAL CONFERENCE ON APPLICATION-SPECIFIC SYSTEMS, ARCHITECTURES AND PROCESSORS, 2008, : 91 - 96