Multi-dimension rule update in a TCAM-based high-performance network security system

被引:0
|
作者
Jeong, Hae-Jin [1 ]
Song, Il-Seop [1 ]
Lee, Yoo-Kyoung [2 ]
Kwon, Taeck-Geun [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci & Engn, 220 Gung Dong, Taejon 305764, South Korea
[2] Elect & Telecommun Res Inst, Taejon 305701, South Korea
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network security systems such as firewall and intrusion prevention system (IPS) have packet classification rule to allow or protect the network traffic. In addition, they are forced to provide multi-gigabit speed in order to deploy the current Internet backbone which requires gigabit Ethernet (GbE), 10 GbE, OC-192, etc. in order to support high-performance packet classification in the network security system, a Ternary Content Addressable Memory, i.e., TCAM accelerates flow identification with classification rules. The TCAM, however, matches the first rule among multiple matched rules, so the ordering of TCAM entries is strictly kept while rules are added or deleted. To keep the ordering in a TCAM, some existing TCAM entries should move to other empty space which impacts the data path processing in the network security system. In this paper, we have proposed a rule update algorithm which reduces the number of TCAM entry movement by the partial ordering of TCAM entry groups instead of the sequential ordering. Our simulation results justify the significant decrement of movement operations where we have applied both generated random rules and real IPS rules, i.e., Snort rules.
引用
收藏
页码:62 / +
页数:2
相关论文
共 50 条
  • [31] HIGH-PERFORMANCE NETWORK AND CHANNEL BASED STORAGE
    KATZ, RH
    PROCEEDINGS OF THE IEEE, 1992, 80 (08) : 1238 - 1261
  • [32] Study On The Effect Of Information Sharing Strategy To Complex Supply Chain System Based On Multi-Dimension View By Simulation
    Jia, Qijun
    Guo, Wei
    Li, Bin
    2007 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-15, 2007, : 4847 - +
  • [33] A Novel Fast Face Recognition Algorithm Based on Multi-Dimension Neural Network Model and Boundary Feature Extraction Technique
    Wang, Yifeng
    Yan, Xiangchen
    Zhang, Anqi
    2017 INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATION AND INFORMATICS (ICCCI), 2017,
  • [34] A HIGH-PERFORMANCE NETWORK FOR A DISTRIBUTED-CONTROL SYSTEM
    CUTTONE, G
    AGHION, F
    GIOVE, D
    NUCLEAR INSTRUMENTS & METHODS IN PHYSICS RESEARCH SECTION B-BEAM INTERACTIONS WITH MATERIALS AND ATOMS, 1989, 40-1 : 978 - 980
  • [35] A multi-focal high-performance vision system
    Kuehnlenz, Koja
    Bachmayer, Mathias
    Buss, Martin
    2006 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA), VOLS 1-10, 2006, : 150 - +
  • [36] HIGH-PERFORMANCE CAPILLARY CHROMATOGRAPHY IN A MULTI-GC NETWORK
    ROONEY, TA
    INTERNATIONAL LABORATORY, 1981, 11 (08): : 69 - &
  • [37] An analysis system on network performance evaluation based on fuzzy rule
    Wu Chenwen
    ICCSE'2006: Proceedings of the First International Conference on Computer Science & Education: ADVANCED COMPUTER TECHNOLOGY, NEW EDUCATION, 2006, : 606 - 609
  • [38] Multi-dimension Multi-objective Fuzzy Optimum Dynamic Programming Method with Complicated Information Based on a Maximal-Sum-Rule of Decision Sequence Priority
    Jin, Yingwei
    Qu, Wenyu
    2009 INTERNATIONAL CONFERENCE ON SCALABLE COMPUTING AND COMMUNICATIONS & EIGHTH INTERNATIONAL CONFERENCE ON EMBEDDED COMPUTING, 2009, : 656 - +
  • [39] A high-performance platform-based SoC for information security
    Wu, Min
    Zeng, Xiaoyang
    Han, Jun
    Wu, Yongyi
    Fan, Yibo
    ASP-DAC 2006: 11TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE, PROCEEDINGS, 2006, : 122 - +
  • [40] Multi-layered based network security defense system
    Sun, Zhi-Xin
    Ren, Zhi-Guang
    Yang, Xi
    Wang, Cheng
    Tongxin Xuebao/Journal on Communications, 2007, 28 (07): : 61 - 69