• DocumentCode
    3139022
  • Title

    A bare PC NAT box

  • Author

    Tsetse, A.K. ; Wijesinha, Alexander L. ; Karne, Ramesh K. ; Loukili, A.

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Towson Univ., Towson, MD, USA
  • fYear
    2012
  • fDate
    26-28 June 2012
  • Firstpage
    281
  • Lastpage
    285
  • Abstract
    Bare PC systems are of interest to builders of minimalist platforms in the next-generation Internet. The bare platform enables software to run directly on ordinary PC hardware without using any operating system or kernel. Bare PC systems perform better than conventional systems and are immune to attacks that target the underlying operating system. We have designed and implemented a bare PC system to perform the essential function of NAT (Network Address Translation) that occurs at the boundary of all private and public networks including ISP boundaries in homes and businesses. We compared the performance of the bare PC NAT and that of a Linux-based NAT running on the same hardware in a test LAN environment. The results show that the bare PC NAT has significantly better performance than the Linux NAT with respect to inbound and outbound packet processing time, and throughput, regardless of packet size and payload application type. Moreover, there is a 34% improvement in the maximum number of packets per second (pps) over Linux under heavy traffic. Internal timings on the bare PC NAT box indicate that there is plenty of capacity left for implementing supplementary functions such as packet filtering, deep packet inspection, and routing if needed.
  • Keywords
    Internet; computer network security; local area networks; next generation networks; ISP boundaries; LAN environment; PC hardware; attack immunity; bare PC NAT Box; deep-packet inspection; inbound packet processing time; network address translation; next generation Internet; operating system; outbound packet processing time; packet filtering; packet size; payload application type; private network boundary; public network boundary; routing; throughput; Hardware; IP networks; Internet; Linux; Local area networks; Logic gates; NAT; application object; bare PC; home router; network security; operating system;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Information Technology (ICCIT), 2012 International Conference on
  • Conference_Location
    Hammamet
  • Print_ISBN
    978-1-4673-1949-2
  • Type

    conf

  • DOI
    10.1109/ICCITechnol.2012.6285809
  • Filename
    6285809