IP Packing Technique for High-speed Firewall Rule Verification

被引:1
|
作者
Khummanee, Suchart [1 ]
机构
[1] Mahasarakham Univ, Fac Informat, Dept Comp Sci, Talat, Thailand
来源
JOURNAL OF INTERNET TECHNOLOGY | 2019年 / 20卷 / 06期
关键词
Firewall; High-speed firewall; Firewall rule matching; IP packing; Path selection diagram;
D O I
10.3966/160792642019102006006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A network bottleneck is often caused by firewalls installed between network gateways. As a result, the overall performance of networks is significantly dropped. The following solution to resolve such the problem can be achieved by increasing the speed of firewall rule verification. Nowadays, there is an open-source matching framework which is the fastest of rule verification, namely IPSets. It can verify a number of firewall rules against huge packets with O(1) worst case access time. However, IPSets still displays several drawbacks of usability such as rule management, subnet IP address, rule conflicts, and memory usage. This paper proposes a novel firewall structure that can resolve all drawbacks of IPSets, and obtains the optimal speed of firewall rule verification at O(1) of access time, called IPack. According to IPack implementation, the paper applies the sparse matrix to be data structures to maintain firewall rules, the Path Selection Diagram (PSD) to eliminate rule conflicts and IP packing technique to reduce the size of memory space. The experimental results show that IPSets drawbacks can be solved by IPack. Especially, the size of memory space is reduced from O(2(n)) to be O(n) with the same optimal access time and the speed of IPack is still equal to IPSets.
引用
收藏
页码:1737 / 1751
页数:15
相关论文
共 50 条
  • [31] Property-driven functional verification technique for high-speed vision system-on-chip processor
    Nshunguyimfura, Victor
    Yang, Jie
    Liu, Liyuan
    Wu, Nanjian
    JAPANESE JOURNAL OF APPLIED PHYSICS, 2017, 56 (04)
  • [32] Scalable, memory efficient, high-speed IP lookup algorithms
    Sangireddy, R
    Futamura, N
    Aluru, SS
    Somani, AK
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2005, 13 (04) : 802 - 812
  • [33] STM shared access system for high-speed IP communications
    Fujimoto, Y
    Ohtaka, A
    Yamaki, K
    Miki, N
    BROADBAND ACCESS, WDM METRO AND NETWORK MANAGEMENT, 2000, : 110 - 117
  • [34] Measurement of high-speed IP traffic behavior based on routers
    Ma, Xiangjie
    Mao, Junpeng
    Hu, Yuxiang
    Lan, Julong
    Guan, Lian
    Zhang, Baisheng
    ADVANCED PARALLEL PROCESSING TECHNOLOGIES, PROCEEDINGS, 2007, 4847 : 222 - 232
  • [35] A Technique of Determining the Trajectory of a High-Speed Rotor
    A. S. Khvostikov
    A. V. Kosmynin
    V. S. Shchetinin
    A. V. Smirnov
    N. A. Ivanova
    Measurement Techniques, 2016, 59 : 239 - 242
  • [36] Development of a technique for high-speed γ-ray spectrometry
    Gin, D. B.
    Chugunov, I. N.
    Shevelev, A. E.
    INSTRUMENTS AND EXPERIMENTAL TECHNIQUES, 2008, 51 (02) : 240 - 245
  • [37] A HIGH-SPEED COMPUTER TECHNIQUE FOR THE TRANSPORTATION PROBLEM
    DENNIS, JB
    JOURNAL OF THE ACM, 1958, 5 (02) : 132 - 153
  • [38] A TEST TECHNIQUE FOR HIGH-SPEED SAMPLING SYSTEMS
    GARDNER, K
    STORY, M
    ELECTRONIC ENGINEERING, 1982, 54 (663): : 44 - &
  • [39] NEW HIGH-SPEED ROTARY GRINDING TECHNIQUE
    不详
    CUTTING TOOL ENGINEERING, 1970, 22 (7-8): : 18 - &
  • [40] Development of a technique for high-speed γ-ray spectrometry
    D. B. Gin
    I. N. Chugunov
    A. E. Shevelev
    Instruments and Experimental Techniques, 2008, 51 : 240 - 245