DocumentCode
258157
Title
On the performance of DPI signature matching with dynamic priority
Author
Melo, Walt ; Lopes, Phil ; Antonello, R. ; Fernandes, Sueli ; Sadok, Djamel
Author_Institution
Fed. Univ. of Pernambuco, Recife, Brazil
fYear
2014
fDate
23-26 June 2014
Firstpage
1
Lastpage
6
Abstract
Traffic classification and identification plays an important role for several activities in network traffic management, where DPI (Deep Packet Inspection) is one of the most accurate and used techniques. However, inspection of packet payload is highly computing intensive. Several research studies have evaluated different components of DPI systems for application detection, in order to increase the classification speed. Nonetheless, the arrangement of the signatures in the signature set is an open issue and can degrade performance. Depending on the order of signatures, the overall performance of the DPI system can be degraded, leading to loss of packets and incorrect traffic identification. To the best of our knowledge, no previous research has analyzed the impact of the order of the application signatures and how it could be modified to improve the identification speed in a given DPI. In this work, we evaluate the impact of the ordering of signatures in a list and propose a method to dynamically adapt the signature list according to the traffic dynamics. We show the effectiveness of our approach with the most reactive proposed setup, saving more than 50% of processing time. We demonstrate the importance of the order of signatures and propose an effective method that can be used to save processing time. Finally, our method can be combined with other state-of-the-art techniques to achieve an optimal utilization of DPI features.
Keywords
computer network performance evaluation; computer network security; digital signatures; telecommunication traffic; DPI signature matching performance; DPI system components; application detection; deep-packet inspection; dynamic priority; identification speed improvement; incorrect-traffic identification problem; network traffic management; optimal DPI feature utilization; overall performance degradation; packet loss; packet payload inspection; processing time; signature arrangement; signature order; signature set; traffic classification speed; traffic dynamics; traffic identification speed; Automata; Engines; Graphics processing units; Inspection; Payloads; Radiation detectors; Telecommunication traffic; Deep Packet Inspection; Dynamic Priority; Performance Evaluation; Signatures List;
fLanguage
English
Publisher
ieee
Conference_Titel
Computers and Communication (ISCC), 2014 IEEE Symposium on
Conference_Location
Funchal
Type
conf
DOI
10.1109/ISCC.2014.6912553
Filename
6912553
Link To Document