DocumentCode
64644
Title
PPP: Towards Parallel Protocol Parsing
Author
Yiyang Shao ; Yibo Xue ; Jun Li
Author_Institution
Dept. of Autom., Tsinghua Univ., Beijing, China
Volume
11
Issue
10
fYear
2014
fDate
Oct. 2014
Firstpage
106
Lastpage
116
Abstract
Network traffic classification plays an important role and benefits many practical network issues, such as Next-Generation Firewalls (NGFW), Quality of Service (QoS), etc. To face the challenges brought by modern high speed networks, many inspiring solutions have been proposed to enhance traffic classification. However, taking many factual network conditions into consideration, e.g., diversity of network environment, traffic classification methods based on Deep Inspection (DI) technique still occupy the top spot in actual usage. In this paper, we propose a novel classification system employing Deep Inspection technique, aiming to achieve Parallel Protocol Parsing (PPP). We start with an analytical study of the existing popular DI methods, namely, regular expression based methods and protocol parsing based methods. Motivated by their relative merits, we extend traditional protocol parsers to achieve parallel matching, which is the representative merit of regular expression. We build a prototype system, and evaluation results show that significant improvement has been made comparing to existing open-source solutions in terms of both memory usage and throughput.
Keywords
computer network security; protocols; telecommunication traffic; DI technique; PPP; analytical analysis; deep inspection technique; high-speed networks; memory usage; network conditions; network environment diversity; network traffic classification enhancement; parallel matching; parallel protocol parsing; regular expression based methods; throughput; traffic classification methods; Automata; Internet; Parallel processing; Pattern matching; Payloads; Ports (Computers); deep inspection; protocol parsing; regular expression; traffic classification;
fLanguage
English
Journal_Title
Communications, China
Publisher
ieee
ISSN
1673-5447
Type
jour
DOI
10.1109/CC.2014.6969799
Filename
6969799
Link To Document