Multi-dimension rule update in a TCAM-based high-performance network security system

被引:0
|
作者
Jeong, Hae-Jin [1 ]
Song, Il-Seop [1 ]
Lee, Yoo-Kyoung [2 ]
Kwon, Taeck-Geun [1 ]
机构
[1] Chungnam Natl Univ, Dept Comp Sci & Engn, 220 Gung Dong, Taejon 305764, South Korea
[2] Elect & Telecommun Res Inst, Taejon 305701, South Korea
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Network security systems such as firewall and intrusion prevention system (IPS) have packet classification rule to allow or protect the network traffic. In addition, they are forced to provide multi-gigabit speed in order to deploy the current Internet backbone which requires gigabit Ethernet (GbE), 10 GbE, OC-192, etc. in order to support high-performance packet classification in the network security system, a Ternary Content Addressable Memory, i.e., TCAM accelerates flow identification with classification rules. The TCAM, however, matches the first rule among multiple matched rules, so the ordering of TCAM entries is strictly kept while rules are added or deleted. To keep the ordering in a TCAM, some existing TCAM entries should move to other empty space which impacts the data path processing in the network security system. In this paper, we have proposed a rule update algorithm which reduces the number of TCAM entry movement by the partial ordering of TCAM entry groups instead of the sequential ordering. Our simulation results justify the significant decrement of movement operations where we have applied both generated random rules and real IPS rules, i.e., Snort rules.
引用
收藏
页码:62 / +
页数:2
相关论文
共 50 条
  • [41] RESEARCH ON HIGH-PERFORMANCE COMPUTING NETWORK SEARCH SYSTEM BASED ON COMPUTER BIG DATA
    Chen, Xiaogang
    Liu, Dongmei
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2024, 25 (03): : 1833 - 1840
  • [42] RESEARCH ON HIGH-PERFORMANCE COMPUTING NETWORK SEARCH SYSTEM BASED ON COMPUTER BIG DATA
    Chen X.
    Liu D.
    Scalable Computing, 2024, 25 (03): : 1833 - 1840
  • [43] An improved AHB bus frame adapted to a high-performance Network Security Accelerator
    Zhang, Chunming
    Yue, Yao
    Wang, Haixin
    Bai, Guoqiang
    Chen, Hongyi
    EDSSC: 2007 IEEE INTERNATIONAL CONFERENCE ON ELECTRON DEVICES AND SOLID-STATE CIRCUITS, VOLS 1 AND 2, PROCEEDINGS, 2007, : 1159 - 1162
  • [44] A High-Performance Capabilities-Based Network Protocol
    Wolf, Tilman
    Vasudevan, Kamlesh T.
    2009 5TH IEEE WORKSHOP ON SECURE NETWORK PROTOCOLS, 2009, : 1 - 6
  • [45] Blockmon: A High-Performance Composable Network Traffic Measurement System
    Huici, Felipe
    di Pietro, Andrea
    Trammell, Brian
    Hidalgo, Jose Maria
    Ruiz, Daniel Martinez
    d'Heureuse, Nico
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2012, 42 (04) : 79 - 80
  • [46] Design and implementation of a high-performance network intrusion prevention system
    Xinidis, K
    Anagnostakis, KG
    Markatos, EP
    Security and Privacy in the Age of Ubiquitous Computing, 2005, 181 : 359 - 374
  • [47] Rosemary: A Robust, Secure, and High-Performance Network Operating System
    Shin, Seungwon
    Song, Yongjoo
    Lee, Taekyung
    Lee, Sangho
    Chung, Jaewoong
    Porras, Phillip
    Yegneswaran, Vinod
    Noh, Jiseong
    Kang, Brent Byunghoon
    CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 78 - 89
  • [48] Building a high-performance communication framework for network isolation system
    Wu, Haiyan
    Tan, Chengxiang
    Wang, Haihang
    PROCEEDINGS OF 2008 IEEE INTERNATIONAL CONFERENCE ON NETWORKING, SENSING AND CONTROL, VOLS 1 AND 2, 2008, : 1086 - 1091
  • [49] The Effects of High-Performance Cloud System for Network Function Virtualization
    Chung, Wu-Chun
    Wang, Yun-He
    APPLIED SCIENCES-BASEL, 2022, 12 (20):
  • [50] A Design for Multi-Pricing High-Performance Computing System
    Chen, Lung-Pin
    Kao, Mike
    Wu, I-Chen
    Wei, Ting-Han
    INTELLIGENT SYSTEMS AND APPLICATIONS (ICS 2014), 2015, 274 : 1733 - 1742