DocumentCode :
1689543
Title :
A Multi-dimension Rule Update in a TCAM-based High-Performance Network Security System
Author :
Jeong, Hae-Jin ; Song, Il-Seop ; Lee, Yoo-Kyoung ; Kwon, Taeck-Geun
Author_Institution :
Dept. of Comput. Sci. & Eng., Chungnam Nat. Univ., Daejon
Volume :
2
fYear :
2006
Firstpage :
62
Lastpage :
66
Abstract :
Network security systems such as firewall and intrusion prevention system (IPS) have packet classification rule to allow or protect the network traffic. In addition, they are forced to provide multi-gigabit speed in order to deploy the current Internet backbone which requires gigabit Ethernet (GbE), 10 GbE, OC-192, etc. In order to support high-performance packet classification in the network security system, a ternary content addressable memory, i.e., TCAM accelerates flow identification with classification rules. The TCAM, however, matches the first rule among multiple matched rules, so the ordering of TCAM entries is strictly kept while rules are added or deleted. To keep the ordering in a TCAM, some existing TCAM entries should move to other empty space which impacts the data path processing in the network security system. In this paper, we have proposed a rule update algorithm which reduces the number of TCAM entry movement by the partial ordering of TCAM entry groups instead of the sequential ordering. Our simulation results justify the significant decrement of movement operations where we have applied both generated random rules and real IPS rules, i.e., Snort rules
Keywords :
Internet; content-addressable storage; local area networks; multidimensional systems; security of data; telecommunication security; telecommunication traffic; Snort rule; TCAM; data path processing; gigabit Ethernet; intrusion prevention system; multidimensional rule update algorithm; network security system; network traffic; packet classification rule; partial ordering; real IPS rule; ternary content addressable memory; Associative memory; Ethernet networks; Filtering; IP networks; Intelligent networks; Internet; National security; Routing; Spine; Telecommunication traffic;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Information Networking and Applications, 2006. AINA 2006. 20th International Conference on
Conference_Location :
Vienna
ISSN :
1550-445X
Print_ISBN :
0-7695-2466-4
Type :
conf
DOI :
10.1109/AINA.2006.37
Filename :
1620354
Link To Document :
بازگشت