Analysis and Data Retrieval by Filtering Packets in High Speed Routers

نویسنده

  • K. Kumar
چکیده

In this paper, we are going to decompose the operation of multimatch packet classification from the complicated multidimensional search to several single-dimensional searches, and present an asynchronous pipeline architecture based on a signature tree structure to combine the intermediate results returned from single-dimensional searches. By spreading edges of the signature tree across multiple hash tables at different stages, the pipeline can achieve a high throughput via the interstate parallel access to hash tables. Two edge-grouping algorithms are designed to evenly divide the edges associated with each stage into multiple workconserving hash tables. The proposed pipeline architecture outperforms Hyper Cuts and B2PC schemes in classification speed by at least one order of magnitude, while having a similar storage requirement. Particularly, with different types of classifiers of 4K rules, the proposed pipeline architecture is able to achieve a throughput between 26.8 and 93.1 GB/s using perfect hash tables. Multiple string match is an important problem in many application areas of computer for instance there is an increasing demand for fast analysis and data retrieval although there are various kinds of comparison tools that provide aligning and approximate matching most of them are based on exact matching in order to speed up the process. Multiple string match is an important problem in many application areas of computer for instance there is an increasing demand for fast analysis and data retrieval although there are various kinds of comparison tools that provide aligning and approximate matching most of them are based on exact matching in order to speed up the process. Another important usage of multiple string matching algorithms appears in NIDS [network intrusion detection systems]. Snort is a light weight open source NIDS which can filter packets based on predefined rules. Another important usage of multiple string matching algorithms appears in NIDS [network intrusion detection systems]. Snort is a light weight open source NIDS which can filter packets based on predefined rules.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Classifying DDoS packets in high-speed networks

Recently high-speed networks have been utilized by attackers as Distributed Denial of Service (DDoS) attack infrastructure. Services on high-speed networks also have been attacked by successive waves of the DDoS attacks. How to sensitively and accurately detect the attack traffic, and quickly filter out the attack packets are still the major challenges in DDoS defense. Unfortunately most curren...

متن کامل

High-speed router filter for blocking TCP flooding under DDoS attack

Protection from Distributed Denial-of-Service attacks has been of a great interest recently and substantial progress has been made for preventing some attack types. However the bandwidth exhaustion attack remains difficult to prevent because the firewalls or servers cannot prevent it locally and a network-wide collaboration is necessary. The routers in use today are not capable of blocking the ...

متن کامل

Optimal Filtering for Denial of Service Mitigation

An optimal approach to mitigation of flooding denial of service attacks is presented. The objective is to minimize effect of the mitigation while protecting the server. The approach relies on routers filtering enough packets so that the server is not overwhelmed while ensuring that as little filtering is performed as possible. The optimal solution is to filter packets at routers through which t...

متن کامل

Literature Review: Adaptive Analysis of High-Speed Router Performance in Packet-Switched Networks

The Internet is a global, publicly accessible, complex network of interconnected computer networks that uses the standard Internet Protocol(IP) to transmit data by dividing it into smaller units, called packets. These packets pass through routers, that connect separate networks, to reach their destinations. Whenever a packet reaches a router, that router has to decide on the next router on the ...

متن کامل

Non-Blocking Routers Design Based on West First Routing Algorithm & MZI Switches for Photonic NoC

For the first time, the 4- and 5-port optical routers are designed by using the West First routing algorithm for use in optical network on chip. The use of the WF algorithm has made the designed routers to provide non-blocking routing in photonic network on chip. These routers not only are based on high speed Mach-Zehnder switches(Which have a higher bandwidth and more thermal tolerance than mi...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015