Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
碩士 === 國立中興大學 === 資訊科學與工程學系所 === 99 === Packet filters are rules of packet classification for classifying packets based on their header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause some security vulnerabil...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | en_US |
Published: |
2011
|
Online Access: | http://ndltd.ncl.edu.tw/handle/83pj9w |
id |
ndltd-TW-099NCHU5394023 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-099NCHU53940232019-05-15T20:42:09Z http://ndltd.ncl.edu.tw/handle/83pj9w Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters 研究與設計多維度封包分類器的衝突偵測演算法 Chin-Yu Lai 賴秦宇 碩士 國立中興大學 資訊科學與工程學系所 99 Packet filters are rules of packet classification for classifying packets based on their header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause some security vulnerabilities in packet classification based services, e.g. firewalls and access control lists. It is necessary to detect conflicts within a reasonable time period. SBV is the first algorithm designed for multidimensional conflict detection, but it cannot distinguish between overlapping conflict and subset conflict. The problem of subset conflict can be solved by reordering filters, while overlapping conflict cannot. In this paper, we describe how to extract overlapping conflicts by modifying the original SBV algorithm. The modified algorithm can support the range fields in packet filters to generate correct result of overlapping conflict. To further shorten the time of conflict detection, we redefine the bit vectors and deal range fields with boundary address concept to speed up the procedure of conflict detection. Our experimental results show that the new algorithm is two times faster than the modified SBV algorithm in detecting overlapping conflict. 王丕中 2011 學位論文 ; thesis 41 en_US |
collection |
NDLTD |
language |
en_US |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立中興大學 === 資訊科學與工程學系所 === 99 === Packet filters are rules of packet classification for classifying packets based on their header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause some security vulnerabilities in packet classification based services, e.g. firewalls and access control lists. It is necessary to detect conflicts within a reasonable time period. SBV is the first algorithm designed for multidimensional conflict detection, but it cannot distinguish between overlapping conflict and subset conflict. The problem of subset conflict can be solved by reordering filters, while overlapping conflict cannot. In this paper, we describe how to extract overlapping conflicts by modifying the original SBV algorithm. The modified algorithm can support the range fields in packet filters to generate correct result of overlapping conflict. To further shorten the time of conflict detection, we redefine the bit vectors and deal range fields with boundary address concept to speed up the procedure of conflict detection. Our experimental results show that the new algorithm is two times faster than the modified SBV algorithm in detecting overlapping conflict.
|
author2 |
王丕中 |
author_facet |
王丕中 Chin-Yu Lai 賴秦宇 |
author |
Chin-Yu Lai 賴秦宇 |
spellingShingle |
Chin-Yu Lai 賴秦宇 Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters |
author_sort |
Chin-Yu Lai |
title |
Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters |
title_short |
Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters |
title_full |
Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters |
title_fullStr |
Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters |
title_full_unstemmed |
Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters |
title_sort |
study and design of conflict detection algorithms for multidimensional packet filters |
publishDate |
2011 |
url |
http://ndltd.ncl.edu.tw/handle/83pj9w |
work_keys_str_mv |
AT chinyulai studyanddesignofconflictdetectionalgorithmsformultidimensionalpacketfilters AT làiqínyǔ studyanddesignofconflictdetectionalgorithmsformultidimensionalpacketfilters AT chinyulai yánjiūyǔshèjìduōwéidùfēngbāofēnlèiqìdechōngtūzhēncèyǎnsuànfǎ AT làiqínyǔ yánjiūyǔshèjìduōwéidùfēngbāofēnlèiqìdechōngtūzhēncèyǎnsuànfǎ |
_version_ |
1719102707661275136 |