Title :
A bare PC NAT box
Author :
Tsetse, A.K. ; Wijesinha, Alexander L. ; Karne, Ramesh K. ; Loukili, A.
Author_Institution :
Dept. of Comput. & Inf. Sci., Towson Univ., Towson, MD, USA
Abstract :
Bare PC systems are of interest to builders of minimalist platforms in the next-generation Internet. The bare platform enables software to run directly on ordinary PC hardware without using any operating system or kernel. Bare PC systems perform better than conventional systems and are immune to attacks that target the underlying operating system. We have designed and implemented a bare PC system to perform the essential function of NAT (Network Address Translation) that occurs at the boundary of all private and public networks including ISP boundaries in homes and businesses. We compared the performance of the bare PC NAT and that of a Linux-based NAT running on the same hardware in a test LAN environment. The results show that the bare PC NAT has significantly better performance than the Linux NAT with respect to inbound and outbound packet processing time, and throughput, regardless of packet size and payload application type. Moreover, there is a 34% improvement in the maximum number of packets per second (pps) over Linux under heavy traffic. Internal timings on the bare PC NAT box indicate that there is plenty of capacity left for implementing supplementary functions such as packet filtering, deep packet inspection, and routing if needed.
Keywords :
Internet; computer network security; local area networks; next generation networks; ISP boundaries; LAN environment; PC hardware; attack immunity; bare PC NAT Box; deep-packet inspection; inbound packet processing time; network address translation; next generation Internet; operating system; outbound packet processing time; packet filtering; packet size; payload application type; private network boundary; public network boundary; routing; throughput; Hardware; IP networks; Internet; Linux; Local area networks; Logic gates; NAT; application object; bare PC; home router; network security; operating system;
Conference_Titel :
Communications and Information Technology (ICCIT), 2012 International Conference on
Conference_Location :
Hammamet
Print_ISBN :
978-1-4673-1949-2
DOI :
10.1109/ICCITechnol.2012.6285809