Specialized Hardware for Deep Network Packet Filtering

Specialized Hardware for Deep Network Packet Filtering
复制标题

DOI:
10.1007/3-540-46117-5_48
复制
发表时间:
2002-09
期刊:
Architectures for Networking and Communications Systems
影响因子:
--
通讯作者:
Young H. Cho;S. Navab;W. Mangione-Smith
Young H. Cho;S. Navab;W. Mangione-Smith
中科院分区:
其他
文献类型:
--
作者:
Young H. Cho;S. Navab;W. Mangione-Smith

文献摘要

被引文献

相似文献

许多计算机网络通过路由器和交换机中的简单防火墙功能提供有限的安全性。一些对安全性要求较高的网络使用深度包过滤器来捕获简单防火墙无法检测到的数据包。深度数据包过滤器使用规则列表来确定数据包的安全性。由于每个规则代表独立的模式匹配过程,因此在处理这些规则时具有高度的并行性。我们发现,现有的软件和硬件防火墙的底层架构没有充分利用这种并行性。因此,我们在现场可编程门阵列(FPGA)上设计了一个深度包过滤防火墙,以利用并行性,同时保留其可编程性。我们的实现是能够处理超过2.88千兆比特每秒的网络流在Altera EP20K系列FPGA无需手动优化。
Many computer network provide limited security through simple firewall feature in router and switch. Some networks that require higher security use deep packet filter to capture packets that can not be detected by simple firewall. Deep packet filters use list of rules for determining safety of packets. There is a high degree of parallelism in processing these rules because each rule represent independent pattern matching process. We find that the underlying architecture for existing software and hardware firewalls do not fully take advantage of this parallelism. Thus, we design a deep packet filtering firewall on a field programmable gate array (FPGA) to take advantage of the parallelism while retaining its programmability. Our implementation is capable of processing over 2.88 gigabits per second of network stream on an Altera EP20K series FPGA without manual optimization.