DocumentCode :
3243809
Title :
Towards High-Performance Network Intrusion Prevention System on Multi-core Network Services Processor
Author :
Wang, Xiang ; Qi, Yaxuan ; Yang, Baohua ; Xue, Yibo ; Li, Jun
Author_Institution :
Sch. of Software Eng., Univ. of Sci. & Technol. of China, Hefei, China
fYear :
2009
fDate :
8-11 Dec. 2009
Firstpage :
220
Lastpage :
227
Abstract :
Network intrusion prevention system (NIPS) becomes more complex due to the rapid growth of network bandwidth and requirement of network security. However existing solutions, either hardware-based or software-based cannot obtain a good tradeoff between performance and flexibility. In this paper, we propose a parallel NIPS architecture using emerging network services processor. To resolve the problems and bottlenecks of high-speed processing, we investigate the main design aspects which have dramatic impacts on most parallel network security system implementations: efficient and flexible pipeline and parallel processing, flow-level packet-order preserving, and latency hiding of deep packet inspection. To these key points, we address several optimizations and modifications with an architecture-aware design principle to guarantee high performance and flexibility of the NIPS on a network services processor implementation. Performance evaluation shows that, our prototype NIPS on Cavium OCTEON3860 processor can reach line-rate stateful inspection and multi-Gbps deep inspection performance.
Keywords :
multiprocessing systems; parallel architectures; security of data; architecture-aware design principle; deep packet inspection; flow-level packet-order preserving; high-performance network intrusion prevention system; latency hiding; multicore network services processor; network bandwidth; network security requirement; parallel NIPS architecture; parallel network security system; parallel processing; Application specific integrated circuits; Automation; Bandwidth; Costs; Data security; Field programmable gate arrays; High-speed networks; Inspection; Prototypes; Software engineering;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Parallel and Distributed Systems (ICPADS), 2009 15th International Conference on
Conference_Location :
Shenzhen
ISSN :
1521-9097
Print_ISBN :
978-1-4244-5788-5
Type :
conf
DOI :
10.1109/ICPADS.2009.109
Filename :
5395257
Link To Document :
بازگشت