• DocumentCode
    263341
  • Title

    B-tree based two-dimensional early packet rejection technique against DoS traffic targeting firewall default security rule

  • Author

    Nguyen Manh Hung ; Vu Duy Nhat

  • Author_Institution
    Post-Grad. Dept., Mil. Tech. Acad., Hanoi, Vietnam
  • fYear
    2014
  • fDate
    14-17 Dec. 2014
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Regarding to the current computer networks, firewall is vital equipment for ensuring the security of entire systems. With the role of controlling all connected to a network, firewall is the only connection between network need to be protected with outside networks. Improving the speed of classifying and processing packets on firewall shall be highly improved to avoid overload of the firewall in the particular case. In order to implement this, the ideal has been used, based on the characteristics of the filter or the characteristics of the data flow through the firewall in order to minimize the manipulation of a packet in the process of classification, which is the early packet rejection. Some early packet rejection techniques in packet firewall systems have been proposed, such as Field Value Set Cover -FVSC, Self Adjusting Binary Search on Prefix Length - SA-BSPL, Statistical Splaying Filters with Binary Search on Prefix Length - SSF-BSPL. In this paper we carry out the analysis of the main strengths and weakness of the above techniques and propose new two-dimensional early packet rejection technique based on the B-Tree. The proposed technique is compared with other techniques experimentally.
  • Keywords
    computer network security; firewalls; packet switching; tree data structures; 2D early packet rejection technique; B-tree; DoS traffic targeting firewall; SA-BSPL; SSF-BSPL; computer networks; data flow; field value set cover; packet classification; packet firewall systems; packet manipulation; packet processing; packet rejection techniques; security rule; self adjusting binary search on prefix length; statistical splaying filters with binary search on prefix length; systems security; Accuracy; Electronics packaging; Firewalls (computing); IP networks; Matched filters; Vegetation; early packet rejection; firewall; packet classification; security policies in firewall;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence for Security and Defense Applications (CISDA), 2014 Seventh IEEE Symposium on
  • Conference_Location
    Hanoi
  • Type

    conf

  • DOI
    10.1109/CISDA.2014.7035643
  • Filename
    7035643