Positive and Negative Caching Mechanisms for Firewall Acceleration
碩士 === 國立交通大學 === 資訊科學系 === 90 === Firewall is one of the best solutions for protecting their networks and hosts against external attacks and intrusions. Setting up a firewall is turned into a basic protection if you connect Internet. But it has scalability issue on the number of firewall...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2002
|
Online Access: | http://ndltd.ncl.edu.tw/handle/41774314982508394241 |
id |
ndltd-TW-090NCTU0394091 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-090NCTU03940912016-06-27T16:09:00Z http://ndltd.ncl.edu.tw/handle/41774314982508394241 Positive and Negative Caching Mechanisms for Firewall Acceleration 以正面與反面快取機制來加速防火牆的效能 Chih-Ching Chang 張智晴 碩士 國立交通大學 資訊科學系 90 Firewall is one of the best solutions for protecting their networks and hosts against external attacks and intrusions. Setting up a firewall is turned into a basic protection if you connect Internet. But it has scalability issue on the number of firewall rules. As the number of rules increases, per-packet processing time increases and the performance drops. We proposed new positive and negative caching mechanisms instead of modifying existing packet matching algorithm to accelerate firewall and resolve the scalability problem. Positive flow cache is for normal traffic and negative is for abnormal one. We implement our algorithm on the open source firewall IP Filter. Benchmarking results are also provided to further illustrate our acceleration. Compared to original firewall under 500 rules, the result shows that UDP throughput is increased by 13.5 times with packet size 64 bytes and TCP throughput is increased by 1.78 times with windows size 16 Kbytes when using our mechanism. Ying-Dar Lin 林盈達 2002 學位論文 ; thesis 28 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立交通大學 === 資訊科學系 === 90 === Firewall is one of the best solutions for protecting their networks and hosts against external attacks and intrusions. Setting up a firewall is turned into a basic protection if you connect Internet. But it has scalability issue on the number of firewall rules. As the number of rules increases, per-packet processing time increases and the performance drops. We proposed new positive and negative caching mechanisms instead of modifying existing packet matching algorithm to accelerate firewall and resolve the scalability problem. Positive flow cache is for normal traffic and negative is for abnormal one. We implement our algorithm on the open source firewall IP Filter. Benchmarking results are also provided to further illustrate our acceleration. Compared to original firewall under 500 rules, the result shows that UDP throughput is increased by 13.5 times with packet size 64 bytes and TCP throughput is increased by 1.78 times with windows size 16 Kbytes when using our mechanism.
|
author2 |
Ying-Dar Lin |
author_facet |
Ying-Dar Lin Chih-Ching Chang 張智晴 |
author |
Chih-Ching Chang 張智晴 |
spellingShingle |
Chih-Ching Chang 張智晴 Positive and Negative Caching Mechanisms for Firewall Acceleration |
author_sort |
Chih-Ching Chang |
title |
Positive and Negative Caching Mechanisms for Firewall Acceleration |
title_short |
Positive and Negative Caching Mechanisms for Firewall Acceleration |
title_full |
Positive and Negative Caching Mechanisms for Firewall Acceleration |
title_fullStr |
Positive and Negative Caching Mechanisms for Firewall Acceleration |
title_full_unstemmed |
Positive and Negative Caching Mechanisms for Firewall Acceleration |
title_sort |
positive and negative caching mechanisms for firewall acceleration |
publishDate |
2002 |
url |
http://ndltd.ncl.edu.tw/handle/41774314982508394241 |
work_keys_str_mv |
AT chihchingchang positiveandnegativecachingmechanismsforfirewallacceleration AT zhāngzhìqíng positiveandnegativecachingmechanismsforfirewallacceleration AT chihchingchang yǐzhèngmiànyǔfǎnmiànkuàiqǔjīzhìláijiāsùfánghuǒqiángdexiàonéng AT zhāngzhìqíng yǐzhèngmiànyǔfǎnmiànkuàiqǔjīzhìláijiāsùfánghuǒqiángdexiàonéng |
_version_ |
1718324564377731072 |