A Hardware-Based Stateful Packet Inspection System Design and Implementation

碩士 === 國立臺灣大學 === 電機工程學研究所 === 95 === The security-related deficiencies in the TCP/IP protocol make networks vulnerable to intruders. The denial-of-service (DoS) attacks are such intrusions that saturate the target of victim machine with external communications requests, such that it cannot respond...

Full description

Bibliographic Details
Main Authors: Bo-Hong Chen, 陳柏宏
Other Authors: Sheng-De Wang
Format: Others
Language:zh-TW
Published: 2007
Online Access:http://ndltd.ncl.edu.tw/handle/88435845643128728725
id ndltd-TW-095NTU05442109
record_format oai_dc
spelling ndltd-TW-095NTU054421092015-12-07T04:04:12Z http://ndltd.ncl.edu.tw/handle/88435845643128728725 A Hardware-Based Stateful Packet Inspection System Design and Implementation 硬體上的封包狀態檢查系統設計與實作 Bo-Hong Chen 陳柏宏 碩士 國立臺灣大學 電機工程學研究所 95 The security-related deficiencies in the TCP/IP protocol make networks vulnerable to intruders. The denial-of-service (DoS) attacks are such intrusions that saturate the target of victim machine with external communications requests, such that it cannot respond to its intended users. Stateful Packet Inspection (SPI) is a key technology that makes a stateful firewall able to hold in memory significant attributes of connections to prevent DoS attacks, such as SYN flooding, the most common DoS attack on the Internet. In this paper, we first investigate SPI technologies and related session table architectures in order to improve the performance of firewall machines. The PATRICIA tree is good at supporting the expensive match, insert, and delete operations in the session table. In this thesis, we use a kind of PATRICIA tree, called Doubly Link PAT-FM algorithm and improve the delete operations. Finally, we implemented the proposed system in hardware and experimental results show its effectiveness. Sheng-De Wang 王勝德 2007 學位論文 ; thesis 50 zh-TW
collection NDLTD
language zh-TW
format Others
sources NDLTD
description 碩士 === 國立臺灣大學 === 電機工程學研究所 === 95 === The security-related deficiencies in the TCP/IP protocol make networks vulnerable to intruders. The denial-of-service (DoS) attacks are such intrusions that saturate the target of victim machine with external communications requests, such that it cannot respond to its intended users. Stateful Packet Inspection (SPI) is a key technology that makes a stateful firewall able to hold in memory significant attributes of connections to prevent DoS attacks, such as SYN flooding, the most common DoS attack on the Internet. In this paper, we first investigate SPI technologies and related session table architectures in order to improve the performance of firewall machines. The PATRICIA tree is good at supporting the expensive match, insert, and delete operations in the session table. In this thesis, we use a kind of PATRICIA tree, called Doubly Link PAT-FM algorithm and improve the delete operations. Finally, we implemented the proposed system in hardware and experimental results show its effectiveness.
author2 Sheng-De Wang
author_facet Sheng-De Wang
Bo-Hong Chen
陳柏宏
author Bo-Hong Chen
陳柏宏
spellingShingle Bo-Hong Chen
陳柏宏
A Hardware-Based Stateful Packet Inspection System Design and Implementation
author_sort Bo-Hong Chen
title A Hardware-Based Stateful Packet Inspection System Design and Implementation
title_short A Hardware-Based Stateful Packet Inspection System Design and Implementation
title_full A Hardware-Based Stateful Packet Inspection System Design and Implementation
title_fullStr A Hardware-Based Stateful Packet Inspection System Design and Implementation
title_full_unstemmed A Hardware-Based Stateful Packet Inspection System Design and Implementation
title_sort hardware-based stateful packet inspection system design and implementation
publishDate 2007
url http://ndltd.ncl.edu.tw/handle/88435845643128728725
work_keys_str_mv AT bohongchen ahardwarebasedstatefulpacketinspectionsystemdesignandimplementation
AT chénbǎihóng ahardwarebasedstatefulpacketinspectionsystemdesignandimplementation
AT bohongchen yìngtǐshàngdefēngbāozhuàngtàijiǎncháxìtǒngshèjìyǔshízuò
AT chénbǎihóng yìngtǐshàngdefēngbāozhuàngtàijiǎncháxìtǒngshèjìyǔshízuò
AT bohongchen hardwarebasedstatefulpacketinspectionsystemdesignandimplementation
AT chénbǎihóng hardwarebasedstatefulpacketinspectionsystemdesignandimplementation
_version_ 1718146531353165824