IP Packing Technique for High-speed Firewall Rule Verification

被引:1
|
作者
Khummanee, Suchart [1 ]
机构
[1] Mahasarakham Univ, Fac Informat, Dept Comp Sci, Talat, Thailand
来源
JOURNAL OF INTERNET TECHNOLOGY | 2019年 / 20卷 / 06期
关键词
Firewall; High-speed firewall; Firewall rule matching; IP packing; Path selection diagram;
D O I
10.3966/160792642019102006006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A network bottleneck is often caused by firewalls installed between network gateways. As a result, the overall performance of networks is significantly dropped. The following solution to resolve such the problem can be achieved by increasing the speed of firewall rule verification. Nowadays, there is an open-source matching framework which is the fastest of rule verification, namely IPSets. It can verify a number of firewall rules against huge packets with O(1) worst case access time. However, IPSets still displays several drawbacks of usability such as rule management, subnet IP address, rule conflicts, and memory usage. This paper proposes a novel firewall structure that can resolve all drawbacks of IPSets, and obtains the optimal speed of firewall rule verification at O(1) of access time, called IPack. According to IPack implementation, the paper applies the sparse matrix to be data structures to maintain firewall rules, the Path Selection Diagram (PSD) to eliminate rule conflicts and IP packing technique to reduce the size of memory space. The experimental results show that IPSets drawbacks can be solved by IPack. Especially, the size of memory space is reduced from O(2(n)) to be O(n) with the same optimal access time and the speed of IPack is still equal to IPSets.
引用
收藏
页码:1737 / 1751
页数:15
相关论文
共 50 条
  • [21] Performance verification of WCDMA handover on high-speed trains
    Juang, Rong-Terng
    Yeh, Kao-Fa
    Lin, Hsin-Piao
    Lin, Ding-Bing
    International Journal of Electrical Engineering, 2010, 17 (05): : 321 - 326
  • [22] Design and verification of supervisory controller of high-speed train
    Yoo, SP
    Lee, DY
    Il Son, H
    ISIE 2001: IEEE INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS PROCEEDINGS, VOLS I-III, 2001, : 1290 - 1295
  • [23] High-speed link Verification Based on Statistical Inference
    Zeng, Xuan
    Fang, Chenlei
    Huang, Qicheng
    Yang, Fan
    Zhou, Dian
    Cai, Wei
    Shi, Weiping
    2016 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2016, : 906 - 909
  • [24] Efficient High-Speed Interface Verification and Fault Analysis
    Nirmaier, Thomas
    Zaguirre, Jose Torres
    Hong, Eric Liau Chee
    Spirkl, Wolfgang
    Rettenberger, Armin
    Schmitt-Landsiedel, Doris
    2008 IEEE INTERNATIONAL TEST CONFERENCE, VOLS 1 AND 2, PROCEEDINGS, 2008, : 105 - +
  • [25] High-Speed Formal Verification of Heterogeneous Coherence Hierarchies
    Beu, Jesse G.
    Poovey, Jason A.
    Hein, Eric R.
    Conte, Thomas M.
    19TH IEEE INTERNATIONAL SYMPOSIUM ON HIGH PERFORMANCE COMPUTER ARCHITECTURE (HPCA2013), 2013, : 566 - 577
  • [26] High-speed fingerprint verification using an optical correlator
    Stoianov, A
    Souter, C
    Graham, A
    OPTICAL ENGINEERING, 1999, 38 (01) : 99 - 107
  • [27] High-speed fingerprint verification using an optical correlator
    Stoianov, A
    Soutar, C
    Graham, A
    OPTICAL PATTERN RECOGNITION IX, 1998, 3386 : 242 - 252
  • [28] Research on high-speed motion control of green environmental protection production line for high-speed flexible cartridge packing
    Kuiwu L.
    International Journal of Industrial and Systems Engineering, 2022, 40 (04): : 455 - 471
  • [29] An independent function-parallel firewall architecture for high-speed networks (Short paper)
    Fulp, Errin W.
    Information and Communications Security, Proceedings, 2006, 4307 : 292 - 301
  • [30] Verification of high-speed IP packet/Ethernet frame forwarding mechanism, and a study of management functions in Network Router/Bridge
    Miyao, H
    Watanabe, Y
    Fujiwara, H
    Toyoshima, K
    Hayashi, K
    DIGITAL CONVERGENCE FOR CREATIVE DIVERGENCE, VOL I: TECHNICAL SPEECH SESSIONS, 1999, : 222 - 229