DocumentCode :
2528680
Title :
Fast Path Session Creation on Network Processors
Author :
Xu, Bo ; Qi, Yaxuan ; He, Fei ; Zhou, Zongwei ; Xue, Yibo ; Li, Jun
Author_Institution :
Res. Inst. of Inf. Technol., Tsinghua Univ., Beijing
fYear :
2008
fDate :
17-20 June 2008
Firstpage :
573
Lastpage :
580
Abstract :
The security gateways today are required not only to block unauthorized accesses by authenticating packet headers, but also by inspecting connection states to defend against malicious intrusions. Hence session creation rate plays a key role in determining the overall performance of stateful intrusion prevention systems. In this paper, we propose a high-speed session creation scheme optimized for network processors. Main contribution includes: a) A high-performance flow classification algorithm on network processors; b) An efficient TCP three-way handshake scheme designed for fast-path processing using a two-stage intelligent hashing. Experimental results show that: a) The presented parallel optimized flow classification algorithm, Parallel Search Cross-Producting, outperforms the original Cross-Producting and Binary Search Cross-Producting algorithms with 300% and 60% increase of classification speed; b) The proposed fast path three-way handshake scheme, IntelliHash, achieves a TCP connection creation rate over 2M connections per second.
Keywords :
authorisation; computer networks; cryptography; message authentication; microprocessor chips; transport protocols; IntelliHash; TCP connection; TCP three-way handshake scheme; fast-path processing; malicious intrusions; network processors; packet headers authentication; parallel optimized flow classification algorithm; parallel search cross-producting; path session creation; security gateways; stateful intrusion prevention systems; two-stage intelligent hashing; unauthorized accesses; Automation; Classification algorithms; Computer science; Computer security; Data security; Distributed computing; Information science; Information technology; Process control; Random access memory; Classification; Network Processor; Session;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Distributed Computing Systems, 2008. ICDCS '08. The 28th International Conference on
Conference_Location :
Beijing
ISSN :
1063-6927
Print_ISBN :
978-0-7695-3172-4
Electronic_ISBN :
1063-6927
Type :
conf
DOI :
10.1109/ICDCS.2008.33
Filename :
4595929
Link To Document :
بازگشت