Specialized Hardware for Deep Network Packet Filtering
Specialized Hardware for Deep Network Packet Filtering
复制标题
DOI:
10.1007/3-540-46117-5_48
复制
发表时间:
2002-09
期刊:
影响因子:
--
通讯作者:
Young H. Cho;S. Navab;W. Mangione-Smith
中科院分区:
文献类型:
--
作者:
Young H. Cho;S. Navab;W. Mangione-Smith
Many computer network provide limited security through simple firewall feature in router and switch. Some networks that require higher security use deep packet filter to capture packets that can not be detected by simple firewall. Deep packet filters use list of rules for determining safety of packets. There is a high degree of parallelism in processing these rules because each rule represent independent pattern matching process. We find that the underlying architecture for existing software and hardware firewalls do not fully take advantage of this parallelism. Thus, we design a deep packet filtering firewall on a field programmable gate array (FPGA) to take advantage of the parallelism while retaining its programmability. Our implementation is capable of processing over 2.88 gigabits per second of network stream on an Altera EP20K series FPGA without manual optimization.