Title :
Towards System-level Optimization for High Performance Unified Threat Management
Author :
Qi, Yaxuan ; Yang, Baohua ; Xu, Bo ; Li, Jun
Author_Institution :
Tsinghua Univ., Beijing
Abstract :
To build holistic protection against complex and blended network threats, multiple security features need to be integrated into unified security architecture, which requires in a unified threat management (UTM). However, most existing UTMs operate by simply stringing together a number of security applications working independently without system level optimization that streamlines processing flow and leverages shared information and resources to reach high performance. In this paper, a generic framework is proposed to optimize the performance of UTMs at both algorithmic and architectural aspects by exploring the idea of integrated protocol processing (IPP). The algorithm proposed in this paper improves overall protocol processing complexity of ACL and IDS from Theta(log(M) + log(N)) to Theta(log(M +N)) . Experiments on Intel IXP2850 network processor show that our scheme outperforms existing solutions with 30% increase of throughput.
Keywords :
computational complexity; cryptographic protocols; ACL; IPP; high performance unified threat management; holistic protection; integrated protocol processing; protocol processing complexity; security features; system-level optimization; Costs; Home appliances; Information security; Inspection; Intrusion detection; Protection; Protocols; Resource management; Throughput; Turing machines;
Conference_Titel :
Networking and Services, 2007. ICNS. Third International Conference on
Conference_Location :
Athens
Print_ISBN :
978-0-7695-2858-9
DOI :
10.1109/ICNS.2007.126