Using Network Processors for Packet Filtering

نویسندگان

  • Bruce Millard
  • Shyamal Pandya
  • Donald Miller
چکیده

This paper presents a hardware/software design and implementation that uses modern networkprocessors as packet-filtering devices that can be used for advanced network applications such as firewalls, network address translation, intrusion detection, traffic shaping and others. Included are the motivation and design and implementation tradeoffs of a hierarchical and pipelined, packet-filter software package using the Intel IXP 1200 network processor. The approach adapts Linux netfilter/iptables software and interfaces as a framework for providing wirespeed packet filtering for modern high-speed networks with complex traffic demands. The Intel IXP 1200, contained on a PCI card in a standard off-the-self personal computer, provides a hardware base that allows for a three-level, hierarchical multiprocessor software architecture. Also included in this paper is an attempt to quantify performance improvements that can be expected from the next generation of Intel network processors and other similar devices using an extrapolation of the software parameters included in this packet filter design.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Optimized computational Afin image algorithm using combination of update coefficients and wavelet packet conversion

Updating Optimal Coefficients and Selected Observations Affine Projection is an effective way to reduce the computational and power consumption of this algorithm in the application of adaptive filters. On the other hand, the calculation of this algorithm can be reduced by using subbands and applying the concept of filtering the Set-Membership in each subband. Considering these concepts, the fir...

متن کامل

Improvement and parallelization of Snort network intrusion detection mechanism using graphics processing unit

Nowadays, Network Intrusion Detection Systems (NIDS) are widely used to provide full security on computer networks. IDS are categorized into two primary types, including signature-based systems and anomaly-based systems. The former is more commonly used than the latter due to its lower error rate. The core of a signature-based IDS is the pattern matching. This process is inherently a computatio...

متن کامل

Design and Implementation of a MultiDimensional Packet Classifier on Network Processor

Network Processors (NPs) are emerging as very promising platforms for developing network devices of Next Generation Internet, due to their capability to combine the flexibility of generalpurpose processors with the high performance features of hardware-based systems. They represent especially the most suitable solutions for implementing complex tasks related to QoS, such as packet classificatio...

متن کامل

Design and Practical Implementation of a New Markov Model Predictive Controller for Variable Communication Packet Loss in Network Control Systems

The current paper investigates the influence of packet losses in network control systems (NCS’s) using the model predictive control (MPC) strategy. The study focuses on two main network packet losses due to sensor to controller and controller to actuator along the communication paths. A new Markov-based method is employed to recursively estimate the probability of time delay in controller to ac...

متن کامل

High-speed packet filtering utilizing stream processors

Parallel firewalls offer a scalable architecture for the next generation of high-speed networks. While these parallel systems can be implemented using multiple firewalls, the latest generation of stream processors can provide similar benefits with a significantly reduced latency due to locality. This paper describes how the Cell Broadband Engine (CBE), a popular stream processor, can be used as...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005