DocumentCode
3441327
Title
DPRP: Distributed Parallelled Rule Pre-matchings for NIDS: A Possible Way to Deploy Middlebox in Future Internet
Author
Zhang Yi ; Sun Zhigang
Author_Institution
Sch. of Comput., Nat. Univ. of Defense Technol., Changsha, China
fYear
2013
fDate
3-4 Dec. 2013
Firstpage
236
Lastpage
240
Abstract
Influenced by cloud computing and emerging software define network(SDN), today´s Internet is changing. In this exciting background, how to deploy middle box functions is widely studied. Main trend is enterprise should outsourcing its middle box functionalities to third party, such as to public cloud[8] or to feather provider[7]. In this paper, we argue that we should not only study where to deploy the middle box functionalities, but also how to implement these functionalities more efficiently and scalable in future Internet. We propose DPRP, a distributed parallel rule pre-matching model for high performance and scalable NIDS implementation. The contribution of DPRP include: (1) DPRP separate hardware accelerator and software modules clearly, and use multiple parallel lightweight rule pre-matching units(RPU) to accelerate rule matching in NIDS. (2)RPU is reconfigurable. NIDS can add/remove RPUs dynamically according to rule matching demand, achieving better balance between performance and resource cost. (3)Hardware accelerators and software modules work in a distributed mode. It is scalable and accommodate to the control mode of the emerging SDN networks. We show the initial design results of RPU design and give more discussions about DPRP. As we know, this is the first work that proposes NIDS being implemented in distributed mode by decoupling hardware accelerators and software modules, which we think a possible way to deploy middle box in future Internet.
Keywords
cloud computing; DPRP; NIDS; RPU design; cloud computing; distributed parallel rule prematching model; emerging SDN networks; future Internet; hardware accelerators; middle box functionalities; multiple parallel lightweight rule prematching units; outsourcing; public cloud; software define network; software modules; Field programmable gate arrays; Hardware; IP networks; Message systems; Middleboxes; Software; NIDS; SDN; middlebox;
fLanguage
English
Publisher
ieee
Conference_Titel
Software Engineering (WCSE), 2013 Fourth World Congress on
Conference_Location
Hong Kong
Print_ISBN
978-1-4799-2882-8
Type
conf
DOI
10.1109/WCSE.2013.43
Filename
6754293
Link To Document