Title :
AntiWorm NPU-based Parallel Bloom filters in Giga-Ethernet LAN
Author :
Chen, Zhen ; Lin, Chuang ; Ni, Jia ; Ruan, Dong-Hua ; Zheng, Bo ; Tan, Zhang-Xi ; Jiang, Yi-Xin ; Peng, Xue-Hai ; Luo, An-An ; Zhu, Bing ; Yue, Yao ; Wang, Yang ; Ungsunan, Peter ; Ren, Feng-yuan
Author_Institution :
Phone: 86-10-62772487, Fax: 86-10-62771138, E-mail: zhenchen@csnet1.cs.tsinghua.edu.cn.
Abstract :
In this paper, an AntiWorm system based on the Intel IXP Network Processor was implemented using the Parallel Bloom filters technique. The AntiWorm system consists of two components: Bloom filters and Exact Matching engines. The Parallel Bloom filters can identify the suspicious traffic quickly and effectively, and then dispatch them to Exact Matching engines for further investigation. Both the principles and the implementation of the AntiWorm system are introduced in detail. With the consideration of the system performance parameters, two feasible implementation solutions are investigated and the advantages and disadvantages are also compared. The selections of configuration parameters of the AntiWorm system are also discussed. A hash scheme based on MD5´s function is proposed for implementing fast hash functions. To test the performance of the AntiWorm system, such as throughput and delay, some experiments are carried out with different simulated traffic condition. The internal statistics of IXP network processor are also collected and analyzed for optimizing the system performance. To demonstrate the operation of the AntiWorm system, assaults by Worm Blaster are used in the test bed, and the experimental results prove the effectiveness of the AntiWorm system. The Software Package WormDetector1.0 is also provided as a software release from the research.
Keywords :
Delay; Engines; Local area networks; Matched filters; Statistical analysis; System performance; System testing; Telecommunication traffic; Throughput; Traffic control; Computer Networks; IXP Network Processor; Network Processors; Network Security; Parallel Bloom filters; Worm Blaster; Worms;
Conference_Titel :
Communications, 2006. ICC '06. IEEE International Conference on
Conference_Location :
Istanbul
Print_ISBN :
1-4244-0355-3
Electronic_ISBN :
8164-9547
DOI :
10.1109/ICC.2006.255083