DocumentCode
2239226
Title
Efficient multi-match packet classification with TCAM
Author
Yu, Fang ; Katz, Randy H.
Author_Institution
Dept. of Electr. Eng. & Comput. Sci., California Univ., Berkeley, CA, USA
fYear
2004
fDate
25-27 Aug. 2004
Firstpage
28
Lastpage
34
Abstract
Today´s packet classification systems are designed to provide the highest priority matching result, e.g., the longest prefix match, even if a packet matches multiple classification rules. However, new network applications, such as intrusion detection systems, require information about all the matching results. We call this the multi-match classification problem. In several complex network applications, multi-match classification is immediately followed by other processing dependent on the classification results. Therefore, classification should be even faster than the line rate. Pure software solutions cannot be used due to their slow speeds. We present a solution based on ternary content addressable memory (TCAM), which produces multi-match classification results with only one TCAM lookup and one SRAM lookup per packet - about ten times fewer memory lookups than a pure software approach. In addition, we present a scheme to remove the negation format in rule sets, which can save up to 95% of TCAM space compared with the straight forward solution. We show that using our pre-processing scheme, header processing for the SNORT rule set can be done with one TCAM and one SRAM lookup using a 135 KB TCAM.
Keywords
computer networks; content-addressable storage; packet switching; table lookup; 135 KB; SRAM lookup; header processing; intrusion detection systems; multi-match packet classification; negation format; rule sets; ternary content addressable memory; Application software; Associative memory; CADCAM; Complex networks; Computer aided manufacturing; Computer crime; Computer worms; Delay; Intrusion detection; Random access memory;
fLanguage
English
Publisher
ieee
Conference_Titel
High Performance Interconnects, 2004. Proceedings. 12th Annual IEEE Symposium on
Print_ISBN
0-7803-8686-8
Type
conf
DOI
10.1109/CONECT.2004.1375197
Filename
1375197
Link To Document