Title :
B-tree based two-dimensional early packet rejection technique against DoS traffic targeting firewall default security rule
Author :
Nguyen Manh Hung ; Vu Duy Nhat
Author_Institution :
Post-Grad. Dept., Mil. Tech. Acad., Hanoi, Vietnam
Abstract :
Regarding to the current computer networks, firewall is vital equipment for ensuring the security of entire systems. With the role of controlling all connected to a network, firewall is the only connection between network need to be protected with outside networks. Improving the speed of classifying and processing packets on firewall shall be highly improved to avoid overload of the firewall in the particular case. In order to implement this, the ideal has been used, based on the characteristics of the filter or the characteristics of the data flow through the firewall in order to minimize the manipulation of a packet in the process of classification, which is the early packet rejection. Some early packet rejection techniques in packet firewall systems have been proposed, such as Field Value Set Cover -FVSC, Self Adjusting Binary Search on Prefix Length - SA-BSPL, Statistical Splaying Filters with Binary Search on Prefix Length - SSF-BSPL. In this paper we carry out the analysis of the main strengths and weakness of the above techniques and propose new two-dimensional early packet rejection technique based on the B-Tree. The proposed technique is compared with other techniques experimentally.
Keywords :
computer network security; firewalls; packet switching; tree data structures; 2D early packet rejection technique; B-tree; DoS traffic targeting firewall; SA-BSPL; SSF-BSPL; computer networks; data flow; field value set cover; packet classification; packet firewall systems; packet manipulation; packet processing; packet rejection techniques; security rule; self adjusting binary search on prefix length; statistical splaying filters with binary search on prefix length; systems security; Accuracy; Electronics packaging; Firewalls (computing); IP networks; Matched filters; Vegetation; early packet rejection; firewall; packet classification; security policies in firewall;
Conference_Titel :
Computational Intelligence for Security and Defense Applications (CISDA), 2014 Seventh IEEE Symposium on
Conference_Location :
Hanoi
DOI :
10.1109/CISDA.2014.7035643