DocumentCode :
3608095
Title :
Modelling and analysis of rule-based network security middleboxes
Author :
Salah, Khaled ; Chaudary, Aslam
Author_Institution :
Electr. & Comput. Eng. Dept., Khalifa Univ. of Sci., Sharjah, United Arab Emirates
Volume :
9
Issue :
6
fYear :
2015
Firstpage :
305
Lastpage :
312
Abstract :
This study presents an analytical model for rule-based network security middleboxes as those of network firewalls, intrusion detection systems and email spam filters. In these systems, incoming packets carrying requests arrive at the middlebox and obtain queued for processing in multiple stages. The stages consist of first a main stage for packet processing and then subsequent stages of rulebase interrogation in which rules or conditions are checked sequentially until a match is triggered. The service at these stages is characterised to be mutually exclusive; that is, only one stage is active at any time. The authors derive useful formulas that can predict the middlebox performance, taking into account its incoming request rate, the queue size and the processing capacity of the middlebox, and thereby proper engineering capacity of the middlebox can be achieved.
Keywords :
computer network security; knowledge based systems; queueing theory; email spam filters; intrusion detection systems; middlebox performance; middlebox processing capacity; network firewalls; packet processing; queue size; rule-base interrogation; rule-based network security middleboxes;
fLanguage :
English
Journal_Title :
Information Security, IET
Publisher :
iet
ISSN :
1751-8709
Type :
jour
DOI :
10.1049/iet-ifs.2014.0545
Filename :
7295684
Link To Document :
بازگشت