A Hardware-Based Stateful Packet Inspection System Design and Implementation
碩士 === 國立臺灣大學 === 電機工程學研究所 === 95 === The security-related deficiencies in the TCP/IP protocol make networks vulnerable to intruders. The denial-of-service (DoS) attacks are such intrusions that saturate the target of victim machine with external communications requests, such that it cannot respond...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2007
|
Online Access: | http://ndltd.ncl.edu.tw/handle/88435845643128728725 |
id |
ndltd-TW-095NTU05442109 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-095NTU054421092015-12-07T04:04:12Z http://ndltd.ncl.edu.tw/handle/88435845643128728725 A Hardware-Based Stateful Packet Inspection System Design and Implementation 硬體上的封包狀態檢查系統設計與實作 Bo-Hong Chen 陳柏宏 碩士 國立臺灣大學 電機工程學研究所 95 The security-related deficiencies in the TCP/IP protocol make networks vulnerable to intruders. The denial-of-service (DoS) attacks are such intrusions that saturate the target of victim machine with external communications requests, such that it cannot respond to its intended users. Stateful Packet Inspection (SPI) is a key technology that makes a stateful firewall able to hold in memory significant attributes of connections to prevent DoS attacks, such as SYN flooding, the most common DoS attack on the Internet. In this paper, we first investigate SPI technologies and related session table architectures in order to improve the performance of firewall machines. The PATRICIA tree is good at supporting the expensive match, insert, and delete operations in the session table. In this thesis, we use a kind of PATRICIA tree, called Doubly Link PAT-FM algorithm and improve the delete operations. Finally, we implemented the proposed system in hardware and experimental results show its effectiveness. Sheng-De Wang 王勝德 2007 學位論文 ; thesis 50 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立臺灣大學 === 電機工程學研究所 === 95 === The security-related deficiencies in the TCP/IP protocol make networks vulnerable to intruders. The denial-of-service (DoS) attacks are such intrusions that saturate the target of victim machine with external communications requests, such that it cannot respond to its intended users. Stateful Packet Inspection (SPI) is a key technology that makes a stateful firewall able to hold in memory significant attributes of connections to prevent DoS attacks, such as SYN flooding, the most common DoS attack on the Internet. In this paper, we first investigate SPI technologies and related session table architectures in order to improve the performance of firewall machines. The PATRICIA tree is good at supporting the expensive match, insert, and delete operations in the session table. In this thesis, we use a kind of PATRICIA tree, called Doubly Link PAT-FM algorithm and improve the delete operations. Finally, we implemented the proposed system in hardware and experimental results show its effectiveness.
|
author2 |
Sheng-De Wang |
author_facet |
Sheng-De Wang Bo-Hong Chen 陳柏宏 |
author |
Bo-Hong Chen 陳柏宏 |
spellingShingle |
Bo-Hong Chen 陳柏宏 A Hardware-Based Stateful Packet Inspection System Design and Implementation |
author_sort |
Bo-Hong Chen |
title |
A Hardware-Based Stateful Packet Inspection System Design and Implementation |
title_short |
A Hardware-Based Stateful Packet Inspection System Design and Implementation |
title_full |
A Hardware-Based Stateful Packet Inspection System Design and Implementation |
title_fullStr |
A Hardware-Based Stateful Packet Inspection System Design and Implementation |
title_full_unstemmed |
A Hardware-Based Stateful Packet Inspection System Design and Implementation |
title_sort |
hardware-based stateful packet inspection system design and implementation |
publishDate |
2007 |
url |
http://ndltd.ncl.edu.tw/handle/88435845643128728725 |
work_keys_str_mv |
AT bohongchen ahardwarebasedstatefulpacketinspectionsystemdesignandimplementation AT chénbǎihóng ahardwarebasedstatefulpacketinspectionsystemdesignandimplementation AT bohongchen yìngtǐshàngdefēngbāozhuàngtàijiǎncháxìtǒngshèjìyǔshízuò AT chénbǎihóng yìngtǐshàngdefēngbāozhuàngtàijiǎncháxìtǒngshèjìyǔshízuò AT bohongchen hardwarebasedstatefulpacketinspectionsystemdesignandimplementation AT chénbǎihóng hardwarebasedstatefulpacketinspectionsystemdesignandimplementation |
_version_ |
1718146531353165824 |