IP Packing Technique for High-speed Firewall Rule Verification

被引:1
|
作者
Khummanee, Suchart [1 ]
机构
[1] Mahasarakham Univ, Fac Informat, Dept Comp Sci, Talat, Thailand
来源
JOURNAL OF INTERNET TECHNOLOGY | 2019年 / 20卷 / 06期
关键词
Firewall; High-speed firewall; Firewall rule matching; IP packing; Path selection diagram;
D O I
10.3966/160792642019102006006
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
A network bottleneck is often caused by firewalls installed between network gateways. As a result, the overall performance of networks is significantly dropped. The following solution to resolve such the problem can be achieved by increasing the speed of firewall rule verification. Nowadays, there is an open-source matching framework which is the fastest of rule verification, namely IPSets. It can verify a number of firewall rules against huge packets with O(1) worst case access time. However, IPSets still displays several drawbacks of usability such as rule management, subnet IP address, rule conflicts, and memory usage. This paper proposes a novel firewall structure that can resolve all drawbacks of IPSets, and obtains the optimal speed of firewall rule verification at O(1) of access time, called IPack. According to IPack implementation, the paper applies the sparse matrix to be data structures to maintain firewall rules, the Path Selection Diagram (PSD) to eliminate rule conflicts and IP packing technique to reduce the size of memory space. The experimental results show that IPSets drawbacks can be solved by IPack. Especially, the size of memory space is reduced from O(2(n)) to be O(n) with the same optimal access time and the speed of IPack is still equal to IPSets.
引用
收藏
页码:1737 / 1751
页数:15
相关论文
共 50 条
  • [41] A high-speed transceiver architecture implementable as synthesizable IP core
    Wortmann, A
    Simon, S
    Müller, M
    DESIGNERS' FORUM: DESIGN, AUTOMATION AND TEST IN EUROPE CONFERENCE AND EXHIBITION, 2004, : 46 - 51
  • [42] SIMPLIFIED TECHNIQUE OF HIGH-SPEED CAPILLARY CENTRIFUGATION
    NEUHOFF, V
    ANALYTICAL BIOCHEMISTRY, 1968, 23 (02) : 359 - &
  • [43] A high-speed IP routing lookup scheme with fast updates
    Kim, BY
    Choi, YH
    HSNMC 2002: 5TH IEEE INTERNATIONAL CONFERENCE ON HIGH SPEED NETWORKS AND MULTIMEDIA COMMUNICATIONS, 2002, : 167 - 171
  • [44] A Technique of Determining the Trajectory of a High-Speed Rotor
    Khvostikov, A. S.
    Kosmynin, A. V.
    Shchetinin, V. S.
    Smirnov, A. V.
    Ivanova, N. A.
    MEASUREMENT TECHNIQUES, 2016, 59 (03) : 239 - 242
  • [45] A flash function for IP flow selection in high-speed network
    Cheng, Guang
    Gong, Jian
    Tang, Yongning
    DYNAMICS OF CONTINUOUS DISCRETE AND IMPULSIVE SYSTEMS-SERIES B-APPLICATIONS & ALGORITHMS, 2007, 14 : 1494 - 1498
  • [46] On IP based access protocol for high-speed wireless LAN
    Hata, M
    Kawasima, M
    Hamasuna, Y
    Usami, S
    Takumi, I
    ITCC 2003: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: COMPUTERS AND COMMUNICATIONS, PROCEEDINGS, 2003, : 356 - 361
  • [47] QoS routing in high-speed IP networks: framework and issues
    Ma, Yulu
    Cheng, Shiduan
    Gaojishu Tongxin/High Technology Letters, 2000, 10 (05): : 99 - 103
  • [48] Influence of packing density on recording media under high-speed field
    Natl Taiwan Ocean Univ, Keelung, Taiwan
    IEEE Transactions on Magnetics, 1998, 34 (2 pt 1): : 355 - 357
  • [49] Slide Rule for Analyzing High-Speed Motion Picture Data
    Maier, Karl W.
    JOURNAL OF THE SOCIETY OF MOTION PICTURE & TELEVISION ENGINEERS, 1951, 56 (06): : 623 - 634
  • [50] Verification of a high-speed machining model based on neural networks
    Kaldos, A
    Boyle, A
    Schulz, G
    ADVANCES IN MANUFACTURING TECHNOLOGY - XIII, 1999, : 45 - 49