Dual Cuckoo Filter with a Low False Positive Rate for Deep Packet Inspection
نویسندگان
چکیده
Network traffic control and classification have become increasingly dependent on deep packet inspection (DPI) approaches, which are the most precise techniques for intrusion detection prevention. However, increasing volumes link speed exert considerable pressure DPI to process packets with high performance in restricted available memory. To overcome this problem, we proposed dual cuckoo filter (DCF) as a data structure based (CF). The CF can be extended parallel mode called Cuckoo Filter (PCF). employs an extra hash function obtain two potential indices of entries. DCF magnifies superiority no additional Moreover, it mode, resulting referred Dual (PDCF). implementation results show that using PDCF identification tools system time improvements up 2% 30% over PCF, respectively.
منابع مشابه
Elastic Deep Packet Inspection
Deep packet inspection (DPI) systems are required to perform at or near network line-rate speeds, matching thousands of rules against the network traffi c. The engineering performance and price trade-offs are such that DPI is diffi cult to virtualize, either because of very high memory consumption or the use of custom hardware; similarly, a running DPI instance is diffi cult to ‘move’ cheaply t...
متن کاملDeep Packet Inspection with Regular Expression Matching
Deep packet inspection directs, persists, filters and logs IP-based applications and Web services traffic based on content encapsulated in a packet's header or payload, regardless of the protocol or application type. In content scanning, the packet payload is compared against a set of patterns specified as regular expressions. With deep packet inspection in place through a single intelligent ne...
متن کاملA Survey on Deep Packet Inspection for Intrusion Detection Systems
Deep packet inspection is widely recognized as a powerful way which is used for intrusion detection systems for inspecting, deterring and deflecting malicious attacks over the network. Fundamentally, almost intrusion detection systems have the ability to search through packets and identify contents that match with known attacks. In this paper, we survey the deep packet inspection implementation...
متن کاملDeep Packet Inspection Using Message Passing Networks
We propose a solution based on message passing bipartite networks, for deep packet inspection, which addresses both speed and memory issues, which are limiting factors in current solutions. We report on a preliminary implementation and propose a parallel architecture. 1 The Problem, Our Solution and Results Packet content scanning at high speed is crucial to network security and network monitor...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences
سال: 2023
ISSN: ['1745-1337', '0916-8508']
DOI: https://doi.org/10.1587/transfun.2022eap1062