• DocumentCode
    459442
  • Title

    AntiWorm NPU-based Parallel Bloom filters in Giga-Ethernet LAN

  • Author

    Chen, Zhen ; Lin, Chuang ; Ni, Jia ; Ruan, Dong-Hua ; Zheng, Bo ; Tan, Zhang-Xi ; Jiang, Yi-Xin ; Peng, Xue-Hai ; Luo, An-An ; Zhu, Bing ; Yue, Yao ; Wang, Yang ; Ungsunan, Peter ; Ren, Feng-yuan

  • Author_Institution
    Phone: 86-10-62772487, Fax: 86-10-62771138, E-mail: zhenchen@csnet1.cs.tsinghua.edu.cn.
  • Volume
    5
  • fYear
    2006
  • fDate
    38869
  • Firstpage
    2118
  • Lastpage
    2123
  • Abstract
    In this paper, an AntiWorm system based on the Intel IXP Network Processor was implemented using the Parallel Bloom filters technique. The AntiWorm system consists of two components: Bloom filters and Exact Matching engines. The Parallel Bloom filters can identify the suspicious traffic quickly and effectively, and then dispatch them to Exact Matching engines for further investigation. Both the principles and the implementation of the AntiWorm system are introduced in detail. With the consideration of the system performance parameters, two feasible implementation solutions are investigated and the advantages and disadvantages are also compared. The selections of configuration parameters of the AntiWorm system are also discussed. A hash scheme based on MD5´s function is proposed for implementing fast hash functions. To test the performance of the AntiWorm system, such as throughput and delay, some experiments are carried out with different simulated traffic condition. The internal statistics of IXP network processor are also collected and analyzed for optimizing the system performance. To demonstrate the operation of the AntiWorm system, assaults by Worm Blaster are used in the test bed, and the experimental results prove the effectiveness of the AntiWorm system. The Software Package WormDetector1.0 is also provided as a software release from the research.
  • Keywords
    Delay; Engines; Local area networks; Matched filters; Statistical analysis; System performance; System testing; Telecommunication traffic; Throughput; Traffic control; Computer Networks; IXP Network Processor; Network Processors; Network Security; Parallel Bloom filters; Worm Blaster; Worms;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2006. ICC '06. IEEE International Conference on
  • Conference_Location
    Istanbul
  • ISSN
    8164-9547
  • Print_ISBN
    1-4244-0355-3
  • Electronic_ISBN
    8164-9547
  • Type

    conf

  • DOI
    10.1109/ICC.2006.255083
  • Filename
    4024478