DocumentCode :
459442
Title :
AntiWorm NPU-based Parallel Bloom filters in Giga-Ethernet LAN
Author :
Chen, Zhen ; Lin, Chuang ; Ni, Jia ; Ruan, Dong-Hua ; Zheng, Bo ; Tan, Zhang-Xi ; Jiang, Yi-Xin ; Peng, Xue-Hai ; Luo, An-An ; Zhu, Bing ; Yue, Yao ; Wang, Yang ; Ungsunan, Peter ; Ren, Feng-yuan
Author_Institution :
Phone: 86-10-62772487, Fax: 86-10-62771138, E-mail: zhenchen@csnet1.cs.tsinghua.edu.cn.
Volume :
5
fYear :
2006
fDate :
38869
Firstpage :
2118
Lastpage :
2123
Abstract :
In this paper, an AntiWorm system based on the Intel IXP Network Processor was implemented using the Parallel Bloom filters technique. The AntiWorm system consists of two components: Bloom filters and Exact Matching engines. The Parallel Bloom filters can identify the suspicious traffic quickly and effectively, and then dispatch them to Exact Matching engines for further investigation. Both the principles and the implementation of the AntiWorm system are introduced in detail. With the consideration of the system performance parameters, two feasible implementation solutions are investigated and the advantages and disadvantages are also compared. The selections of configuration parameters of the AntiWorm system are also discussed. A hash scheme based on MD5´s function is proposed for implementing fast hash functions. To test the performance of the AntiWorm system, such as throughput and delay, some experiments are carried out with different simulated traffic condition. The internal statistics of IXP network processor are also collected and analyzed for optimizing the system performance. To demonstrate the operation of the AntiWorm system, assaults by Worm Blaster are used in the test bed, and the experimental results prove the effectiveness of the AntiWorm system. The Software Package WormDetector1.0 is also provided as a software release from the research.
Keywords :
Delay; Engines; Local area networks; Matched filters; Statistical analysis; System performance; System testing; Telecommunication traffic; Throughput; Traffic control; Computer Networks; IXP Network Processor; Network Processors; Network Security; Parallel Bloom filters; Worm Blaster; Worms;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, 2006. ICC '06. IEEE International Conference on
Conference_Location :
Istanbul
ISSN :
8164-9547
Print_ISBN :
1-4244-0355-3
Electronic_ISBN :
8164-9547
Type :
conf
DOI :
10.1109/ICC.2006.255083
Filename :
4024478
Link To Document :
بازگشت