PL EN


Preferencje help
Widoczny [Schowaj] Abstrakt
Liczba wyników
Tytuł artykułu

Implementation of the Hardware Packet Classification System

Wybrane pełne teksty z tego czasopisma
Identyfikatory
Warianty tytułu
Języki publikacji
EN
Abstrakty
EN
This article presents the results of research related to the construction of a complete packet classifier, constituting the main element of a hardware-based firewall security system. The developed solution is based on two filter blocks operating in parallel: address filters and network ports filters. The proposed method of filtering network addresses using dedicated TCAM memory is characterized by fast operational speeds and a much more effective usage of FPGA chip resources as compared to commercial versions offered by Xilinx. Similarly, in order to verify network ports, especially taking into account rules that define port ranges, the authors proposes a novel concept based on cascades of elementary RAM16X1D memory available in Xilinx’s Virtex FPGA family circuits. The resulting data processing speed in excess of 160 million of packets per second, coupled with positive results of preliminary tests, make it possible to use the classification system in modern wide bandwidth telecommunications networks.
Rocznik
Strony
97--111
Opis fizyczny
Bibliogr. 4 poz.
Twórcy
autor
autor
Bibliografia
  • [1] Gupta, P., and McKeown, N., Algorithms for packet classification, IEEE Network, Vol. 15, No. 2, Mar./Apr. 2001, pp. 24-32.
  • [2] Sułkowski, G., Twardy, M., and Wiatr, K., Wielościeżkowe równoległe przetwarzanie danych w sprzętowym systemie bezpieczeństwa klasy Firewall, Proceedings of KNWS '08 published in quarterly Pomiary, Automatyka i Kontrola No. 6, Warsaw, 2007, pp. 726-728.
  • [3] Spitznagel, E., Taylor, D., and Turner, J., Packet Classification Using Extended TCAM, Proceedings of the 11th IEEE International Conference on Network Protocols, November 04-07, 2003, p. 120.
  • [4] Qin, H., Sasao, T., and Butler, J., Implementation of LPM Address Generators on FPGAs, Architectures and Applications, Second International Workshop, ARC 2006.
Typ dokumentu
Bibliografia
Identyfikator YADDA
bwmeta1.element.baztech-article-LOD9-0010-0020
JavaScript jest wyłączony w Twojej przeglądarce internetowej. Włącz go, a następnie odśwież stronę, aby móc w pełni z niej korzystać.