Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters

碩士 === 國立中興大學 === 資訊科學與工程學系所 === 99 === Packet filters are rules of packet classification for classifying packets based on their header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause some security vulnerabil...

Full description

Bibliographic Details
Main Authors: Chin-Yu Lai, 賴秦宇
Other Authors: 王丕中
Format: Others
Language:en_US
Published: 2011
Online Access:http://ndltd.ncl.edu.tw/handle/83pj9w
id ndltd-TW-099NCHU5394023
record_format oai_dc
spelling ndltd-TW-099NCHU53940232019-05-15T20:42:09Z http://ndltd.ncl.edu.tw/handle/83pj9w Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters 研究與設計多維度封包分類器的衝突偵測演算法 Chin-Yu Lai 賴秦宇 碩士 國立中興大學 資訊科學與工程學系所 99 Packet filters are rules of packet classification for classifying packets based on their header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause some security vulnerabilities in packet classification based services, e.g. firewalls and access control lists. It is necessary to detect conflicts within a reasonable time period. SBV is the first algorithm designed for multidimensional conflict detection, but it cannot distinguish between overlapping conflict and subset conflict. The problem of subset conflict can be solved by reordering filters, while overlapping conflict cannot. In this paper, we describe how to extract overlapping conflicts by modifying the original SBV algorithm. The modified algorithm can support the range fields in packet filters to generate correct result of overlapping conflict. To further shorten the time of conflict detection, we redefine the bit vectors and deal range fields with boundary address concept to speed up the procedure of conflict detection. Our experimental results show that the new algorithm is two times faster than the modified SBV algorithm in detecting overlapping conflict. 王丕中 2011 學位論文 ; thesis 41 en_US
collection NDLTD
language en_US
format Others
sources NDLTD
description 碩士 === 國立中興大學 === 資訊科學與工程學系所 === 99 === Packet filters are rules of packet classification for classifying packets based on their header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause some security vulnerabilities in packet classification based services, e.g. firewalls and access control lists. It is necessary to detect conflicts within a reasonable time period. SBV is the first algorithm designed for multidimensional conflict detection, but it cannot distinguish between overlapping conflict and subset conflict. The problem of subset conflict can be solved by reordering filters, while overlapping conflict cannot. In this paper, we describe how to extract overlapping conflicts by modifying the original SBV algorithm. The modified algorithm can support the range fields in packet filters to generate correct result of overlapping conflict. To further shorten the time of conflict detection, we redefine the bit vectors and deal range fields with boundary address concept to speed up the procedure of conflict detection. Our experimental results show that the new algorithm is two times faster than the modified SBV algorithm in detecting overlapping conflict.
author2 王丕中
author_facet 王丕中
Chin-Yu Lai
賴秦宇
author Chin-Yu Lai
賴秦宇
spellingShingle Chin-Yu Lai
賴秦宇
Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
author_sort Chin-Yu Lai
title Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
title_short Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
title_full Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
title_fullStr Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
title_full_unstemmed Study and Design of Conflict Detection Algorithms for Multidimensional Packet Filters
title_sort study and design of conflict detection algorithms for multidimensional packet filters
publishDate 2011
url http://ndltd.ncl.edu.tw/handle/83pj9w
work_keys_str_mv AT chinyulai studyanddesignofconflictdetectionalgorithmsformultidimensionalpacketfilters
AT làiqínyǔ studyanddesignofconflictdetectionalgorithmsformultidimensionalpacketfilters
AT chinyulai yánjiūyǔshèjìduōwéidùfēngbāofēnlèiqìdechōngtūzhēncèyǎnsuànfǎ
AT làiqínyǔ yánjiūyǔshèjìduōwéidùfēngbāofēnlèiqìdechōngtūzhēncèyǎnsuànfǎ
_version_ 1719102707661275136