Positive and Negative Caching Mechanisms for Firewall Acceleration

碩士 === 國立交通大學 === 資訊科學系 === 90 === Firewall is one of the best solutions for protecting their networks and hosts against external attacks and intrusions. Setting up a firewall is turned into a basic protection if you connect Internet. But it has scalability issue on the number of firewall...

Full description

Bibliographic Details
Main Authors: Chih-Ching Chang, 張智晴
Other Authors: Ying-Dar Lin
Format: Others
Language:en_US
Published: 2002
Online Access:http://ndltd.ncl.edu.tw/handle/41774314982508394241
id ndltd-TW-090NCTU0394091
record_format oai_dc
spelling ndltd-TW-090NCTU03940912016-06-27T16:09:00Z http://ndltd.ncl.edu.tw/handle/41774314982508394241 Positive and Negative Caching Mechanisms for Firewall Acceleration 以正面與反面快取機制來加速防火牆的效能 Chih-Ching Chang 張智晴 碩士 國立交通大學 資訊科學系 90 Firewall is one of the best solutions for protecting their networks and hosts against external attacks and intrusions. Setting up a firewall is turned into a basic protection if you connect Internet. But it has scalability issue on the number of firewall rules. As the number of rules increases, per-packet processing time increases and the performance drops. We proposed new positive and negative caching mechanisms instead of modifying existing packet matching algorithm to accelerate firewall and resolve the scalability problem. Positive flow cache is for normal traffic and negative is for abnormal one. We implement our algorithm on the open source firewall IP Filter. Benchmarking results are also provided to further illustrate our acceleration. Compared to original firewall under 500 rules, the result shows that UDP throughput is increased by 13.5 times with packet size 64 bytes and TCP throughput is increased by 1.78 times with windows size 16 Kbytes when using our mechanism. Ying-Dar Lin 林盈達 2002 學位論文 ; thesis 28 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立交通大學 === 資訊科學系 === 90 === Firewall is one of the best solutions for protecting their networks and hosts against external attacks and intrusions. Setting up a firewall is turned into a basic protection if you connect Internet. But it has scalability issue on the number of firewall rules. As the number of rules increases, per-packet processing time increases and the performance drops. We proposed new positive and negative caching mechanisms instead of modifying existing packet matching algorithm to accelerate firewall and resolve the scalability problem. Positive flow cache is for normal traffic and negative is for abnormal one. We implement our algorithm on the open source firewall IP Filter. Benchmarking results are also provided to further illustrate our acceleration. Compared to original firewall under 500 rules, the result shows that UDP throughput is increased by 13.5 times with packet size 64 bytes and TCP throughput is increased by 1.78 times with windows size 16 Kbytes when using our mechanism.
author2 Ying-Dar Lin
author_facet Ying-Dar Lin
Chih-Ching Chang
張智晴
author Chih-Ching Chang
張智晴
spellingShingle Chih-Ching Chang
張智晴
Positive and Negative Caching Mechanisms for Firewall Acceleration
author_sort Chih-Ching Chang
title Positive and Negative Caching Mechanisms for Firewall Acceleration
title_short Positive and Negative Caching Mechanisms for Firewall Acceleration
title_full Positive and Negative Caching Mechanisms for Firewall Acceleration
title_fullStr Positive and Negative Caching Mechanisms for Firewall Acceleration
title_full_unstemmed Positive and Negative Caching Mechanisms for Firewall Acceleration
title_sort positive and negative caching mechanisms for firewall acceleration
publishDate 2002
url http://ndltd.ncl.edu.tw/handle/41774314982508394241
work_keys_str_mv AT chihchingchang positiveandnegativecachingmechanismsforfirewallacceleration
AT zhāngzhìqíng positiveandnegativecachingmechanismsforfirewallacceleration
AT chihchingchang yǐzhèngmiànyǔfǎnmiànkuàiqǔjīzhìláijiāsùfánghuǒqiángdexiàonéng
AT zhāngzhìqíng yǐzhèngmiànyǔfǎnmiànkuàiqǔjīzhìláijiāsùfánghuǒqiángdexiàonéng
_version_ 1718324564377731072