The Experts below are selected from a list of 81876 Experts worldwide ranked by ideXlab platform

Gettysburg College - One of the best experts on this subject based on the ideXlab platform.

  • Course catalogue; Gettysburg College course catalogue; Gettysburg College bulletin; Pennsylvania College of Gettysburg bulletin; Pennsylvania College bulletin; Catalogue of the officers and students in Pennsylvania College; Gettysburg catalogue
    2005
    Co-Authors: Gettysburg College
    Abstract:

    Course Catalogue 2005-2006 %=!M' ^ # *=*' Table ofContents GETTYSBURG COLLEGE—THE COMMUNITY Admission Evaluation, Campus Visit, Admission with Advanced Credit and Placement, International Student Admission, Statistical Summary EXPENSES/SERVICES Comprehensive Fee Plan, VA Benefits, Payment Plans, Insurance FINANCIAL AID Merit-Based Scholarships, Need-Based Financial Aid STUDENT SERVICES Residence Life, International Student Advising, Intercultural Advancement, Dining, Health Center, Counseling, Career Development, Safety and Security COLLEGE UFE Student Conduct, Honor Code, College Union, Student Government, Programs and Activities, Campus Media, Greek Organizations, Religious Spiritual Life, Center for Public Service, Athletics, Campus Recreation FACIUTIES Academic Purposes, Degree Requirements, Individual Mjijor, Academic Advising, Senior Scholars Seminar, Academic Internships, The Gettyshi'^ Review, Off-Campus Study, Dual- Degree Programs, Preprofessional Studies Registration, Grading, Residence Requirements, Transcripts, Withdrawral Graduation Honors, Deans Lists, Phi Beta Kappa, Alpha Lambda Delta COURSES OF STUDY ENDOWMENT FUNDS Theprovisions ofthis catalogue are not to be regarded as an irrevocable contract between the College and the student The College reserves the right to change any provision or requirement at any time. This right to changeprovisions and requirements includes, but is not limited to, the right to reduce or eliminate course offerings in academicfields and to add requirementsforgraduation. REGISTER Trustees, Faculty, Administration Gettysburg College Course Catalogue 2005-2006 Getwsburg, Penns\'lv.\nl\ Digitized by the Internet Archive in 2010 with funding from Lyrasis Members and Sloan Foundation http://www.archive.org/details/gettysbu20052006gett Gettysburg College—Mission Statement MISSION STATEMENT G('llysl)urg Colkge, a nalional, residential, undergraduate college committed to a liberal education, prepares students to be actixw leaders andparticipants in a changing world. This statement is grounded in the core values of the institution: • The worth and digni^ of all people and the Hmitless value of their intellectual potential; • The power of a liberal arts education to help students develop critical thinking skills, broad vision, effective commimications, a sense of the inter-relatedness of all knowledge, sensitivity to the human condition, and a global perspective, all necessary to enable students to realize their full potential for responsible citizenship; • The enrichment of the traditional liberal arts and sciences curriculum with the most promising intellectual developments of the age; • The free and open marke^lace of ideas and the exploration of the ethical and spiritual dimensions of those ideas, both indispensable to helping students learn to determine which have lasting value; • The value of a lifelong commitment to service, and the role of the College in both providing an example of public senace for students and fostering a commitment to service among our young people; and • A belief that a residential college is the most effective means of promoting the personal interacdon between student and professor, and student and student which develops the community that is the heart of a liberal arts education. (APPROMD andREUSED by theFaculty Council on October 30, 2002) (Adopted by Board ofTrustees,Januaty 2003) Gettysburg College—The Community A HERITAGE OF EXCELLENCE AtGettysburg Colkge, we are committed topreparing ourstudentsfor the opportunities ofthis changing luorld. OurfoundingprincipU's embrace a rigorous liberal arts education thatfosters a globalperspective, a spitit ofcollaboration, a dedication topublic sendee, and an enriching Iampus life. We belieiie that this approach to education instills in Gettysburg Colkge students a desire to lead engaged, enlightened, and energetic lives. Dedicated to Great Work The histoiT of Getnsburg College has intersected with events of pohtical, social, and global significance. Chartered in 1832, Gettysburg ( '.ollege was born in an era of dramatic change. The young United States faced political and iconomic challenges, pioneers pushed into new frontiers, and academic institutions were established that would become today's finest ( olleges and universities. In 1863, Union and Confederate soldiers clashed on the fields of Gettysburg, Pennsylvania. Pennsylvania Hall, the first building on campus, sen'ed as a temporarv hospital for the woimded from both sides. Today, its name appears on the National Register of Historic Places. On November 19, 1863, Gett\'sburg College students witnessed the legendan,' address of Abraham Lincoln, which to this day links our country's sixteenth president with the site of the most famous battle of the .\merican Cavil War. Years later, President Dwight D. Eisenhower arrived at Gettysburg, sharing his experience and insights as a nadonal leader. Following his presidency, Eisenhower returned to Gettysburg to write his memoirs in what is now Eisenhower House, the College's admissions office. \^isits by Elie Wiesel, General Colin Powell, and leaders from the American Civil Liberties Union, the civil rights movement, and the Peace Corps continue to demonstrate Gettysburg College's dedication to issues of global importance. Today, Gettysburg College continues to champion independent thinking and public action by providing students with the abilities to reason and communicate, and the incentive to make a difference in our world. A Gettv'sburg College education blends a rigorous foundation in the sciences, the social sciences, and the humanities with a highly personal atmosphere of challenge and support. The curricular and co-curricular opportunities are carefully designed to stimulate critical thinking, encourage public service, and instill a global perspective in our students. At Gettv'sburg College, more than 2,500 young women and men learn, explore, discover, and create with the challenge and support of 180 full-time faculty members. Approximately 95 Percent of the teaching facultv' hold the doctorate or the highest earned degree in their field. As devoted as thev are to their chosen fields of study, Gettysburg College faculty are equally dedicated to the success of their students. Small classes averaging eighteen students and a student/facultv' ratio of 11:1 foster an open and informal exchange of ideas, a sense of commimity and collaboration, and endless opportunities for accomplishment. As part of Gettysburg College's balanced imdergraduate program in the liberal arts and sciences, students may choo.se from thirt)-eight majors, pursue interdisciplinar)' and self-designed majors, or complete one of several cooperative and dual-degree programs. The College also provides a certification in elementary and secondarv' education, and preparation for professional schools in law, medicine, and the allied health sciences. Study abroad, internship, and student/faculty research opportunities are plentiful and encouraged. We welcome your interest in Gettysburg College. GETTYSBURG-AT-A-GLANCE Type of College: Four-year, co-educational residential college of liberal arts and sciences founded in 1832. Enrollment: More than 2,500 students (Approximately one-half are men and one-half are women), representing 40 states and 35 foreign coimtries. Approximately 90 Percent of the students live on campus in more than forty-three residence halls, including theme halls, apartment complexes, and special interest houses. Location: Beaiuiful 200-acre campus with over 60 buildings. The College is adjacent to the Gettysburg National Park. Gett\'sburg, Pennsylvania, is 36 miles from Harrisburg, 55 miles from Baltimore, 80 miles from Washington, D.C., 117 miles from Philadelphia, and 212 miles from New York City. Academic Information: Thirty-eight majors, individual majors, double majors, minors, and an extensive area studies program. Student/ faculty ratio of 11:1 with an average class size of 18 students. More than 180 full-time faculty with Approximately 95 Percent of the permanent faculty holding the doctorate or highest earned degree in their fields. One of only 19 chapters of Phi Beta Kappa in Pennsylvania. Honorary or professional societies in 16 academic areas. Academic Honor Code in effect since 1957. Special Programs: Extensive study abroad programs; internships; Washington Semester (government and politics, economic policy, ethical issues and public affairs, foreign policy, public administration, justice, urban studies, journalism, art and architecture, arts and humanities); United Nations Semester; dual-degree programs in engineering, nursing, optometry, and forestry' and environmental studies; cooperative program in marine biology; certification in elementary and secondary education; pre-health and pre-law counseling. Cooperative college consortium with Dickinson and Franklin 8c Marshall Colleges. Exceptional Facilities: Musselman Library; full network capabilities in all campus buildings and each residence hall room, high-speed access to the Internet, microcomputer laboratories and workstations; wireless network; state-of-the-art science facilities, including two electron microscopes (transmission and scanning units), a PN-250 Van de Froot HVEC proton accelerator, four spectrometers (Fourier Transform Infrared, NMR, UV-visible, and Nd:YAG laser), greenhotise, planetarium, observatory, and optics and plasma physics laboratories; the Child Study Center; extensive facilities for the fine arts, music, and drama; writing center; comprehensive physical education complex; health center and covmseling services; Center for Career Development; College Union Building, student activities center; Center for Public Service. Student Activities: Student Senate; Campus Activities Board; FM radio station; yearbook; newspaper; literary magazine; full range of musical groups, including choirs, marching, symphonic, and jazz bands, college/community orchestra, and numerous ensembles; black student tmion; international student club; theatre groups; special interest groups; more than 130 clubs and commimity senice organizadons; more than 1,000 leadership positions. Athletics: Division III level within the Centennial Conference. Twelve sports for men and twelve sports for women at the varsity level. A wide array of intramiual and club sports to satisfy various interests and levels of skill. Religious Life: Lutheran related. Programs for students of all faiths coordinated through the College Chapel, including Newman Association, Muslim Student Association, and Hillel. School Colors: Orange and blue. Admission ADMISSION Gettysburg College students comefrom a imde vartety ofbackgrounds andsecondary school programs. The College encourages applicationsfrom students ofdiffering ethnic, religious, racial economic, andgeographic backgrounds. The admission staffencaurages applications from students who have demonstrated a capacityfor academic achievement, responsiveness to intellectual challenge, eagerness to contribute their special talents to the College community, and an awareness of social responsibility. Such personsgivepromise ofpossessing the ability and the motivation that will enable them toproftfrom tlie many opporlunities that the College offers. Campus Information A wide variety of information about Gettysburg College can be found in the College's various publications. Prospective students may request College publications by contacting: Director of Admission Eisenhower House Gettysburg College Gettysburg, PA 17325 717-337-6100; 800-431-0803 (Fax) 717-337-6145 adnuss@gettysbtu'g.edu www.gettysburg.edu Admission Evaluation Since the competition for admission is highlv competitive, the admission staff gives careful consideration to each application. Its decisions are based on three categories of evidence described below. Ex'idence ofhigh acodemir achievement as indicated try the secondary school record. The College considers grades in academic courses, quality and distribution of subjects, and rank in class as highly significant parts of the applicant's credentials. Participation in accelerated, enriched, and advanced placement courses is highly desirable. The College regards superior facility in the use of the English language and an understanding of fundamental mathematical processes as essential to a successful college experience. It also assumes gradtiation from an approved secondary school or home-school program. Evidence ofability to do high quality college ivork as indicated by aptitude and achievement test results. The SAT I of the College Board or the test results of the American College Testing (ACT) program are required of all candidates. Evidence ofpersonal qualities. There is high interest in individtials of character who will contribute in positive ways to the College community. In estimating such qualities, the College relies on what students say about themselves; the confidential statements from secondary school principals, headmasters, teachers, and guidance counselors; and on personal appraisals by its alumni and friends. Essentially, anv evidence of in-depth involvement in secondar)' school activities and/or participation in communit)' affairs (especially volunteer services) is favorably considered in the admission process. The Campus Visit Personal interviews, group sessions, and campus tours are strongly recommended: they give prospective students a personal look at the opportunities and variet)' offered in the academic and extracurricular program. Gettysburg students give generously of their time and talents to the College and surrounding communit)'. and are pleased to share their experiences with visiting students. Prospective students are welcome to visit the campus for a tour and/or a group session at any time. Interviews may be scheduled between April 1 of the junior year and March 1 of the senior year. Students considering a major in art or music should make their interest known when requesting an interview, so that arrangements can be made for an appointment with a member of the department concerned. Students can arrange an interview, group session, or campus tour by calling the Office of Admissions at 717-337-6100 or 800431-0803. During the academic year, the admissions office is open from 9:00 to 5:00 on weekdays and from 9:00 to 12:00 on Saturdays; summer hours are between 8:00 and 4:30 weekdays. Admission Process Early Dfcisiuii. Students lor whom Gettysburg College is a first choice are strongly encouraged to apply for Early Decision admission. The deadline for Early Decision I is November 15; the deadline for Early Decision II is January 15. A non-refundable fee of $45 must be sent with the application. Those students accepted under this admission plan are obligated to enroll at Gett^'sblug College and to withdraw applications submitted to other institutions. Notification of the decision on admission will be mailed within a month after the deadline. Payment of a non-refundable advance fee of $500 is required to validate this offer of acceptance. Although the Early Decision applicant should take the SAT I or the ACT in the jimior year, scores from the October/November testing date of the senior year will also be considered. Those students submitting applications for Early Decision who are not offered acceptance at that time will automatically be considered for Regular Decision admission upon receipt of subsequent semester grades and test scores from the senior year. RegularDecision. Students applying as Regular Decision candidates to Gett)'sburg College should submit an application during the fall of their senior year and by February 15; a nonrefundable fee of $45 must be sent with the application. Most offers of acceptance will be mailed by early April, after the receipt of November, December, or January SAT I results and senior year first semester grades. Results for the SAT I or ACT taken prior to the senior year may be used to satisfy test requirements. Payment of a nonrefundable advance fee of $500 is required to validate the offer of acceptance. Since Gettysburg College subscribes to the principle of the Candidate's Reply Date, students have until May 1 to make their decision and pay the advance fee. All acceptances by Gett\'sburg College are conditional and based upon students continuing to do satisfactory work in all subjects, avoiding disciplinaiy circumstances, and earning a secondary school diploma. Admission with Advanced Credit and Placement Students who have taken atlxianrt'dplarenienl courses in secondary school and wish to be considered for advanced credit or placement must take advanced placement tests of The College Board. All entering students who submit a score of four or five on these tests may receive one course credit for each tested area toward the 32-course graduation requirement. Course credit for advanced placement will be lost if a student takes the equivalent course at Gettysburg. Students who have completed advanced-level or honors courses may be considered for advanced placement. Those high school students who have taken regular courses at t/ie college In'el'm regionally accredited junior or four-year colleges may receive credit for these courses if there has been no duplication of high school units and college credits. Gettysburg College recognizes the quality of the Inleniational Bacealaureale (IB) Diploma in the admission process. In addition, the College awards one course credit in each subject area for Higher Level examination scores of five or higher. Credit for a Higher Level score of four will be given at the discretion of the department. For students who plan to complete their graduation requirements in less than four full years, see the section on residence requirements and schedule limitations for information about planning of the academic program. International Student Admission The College welcomes applications from international students who can read, write, speak, and understand the English langviage with considerable proficiency. International applicants should send the completed application form with official secondary school transcripts, and an explanation of grading procedures; the SAT of The College Board or the test results of the American College Testing (ACT) program; the Test of English as a Foreign Language (TOEFL) results; the application essay; and The College Board Certification of the Finances Form. International students applving for financial aid must also file The College Board's International Student Financial Aid Form. Transfer Student Admission Gettysburg welcomes applications from students interested in transfemng to the College. Transfer students applying for the spring semester should submit their application by December 1 , and students applying for the fall semester should apply by April 15; transfers applying after those preferred dates should do so as soon as possible. Reactivating the application. Students who have previously applied to Gettysburg College and now wish to reactivate their application should send a letter or e-mail message requesting a reactivation. In order to update and complete the application, send the final secondary school transcript, SAT and/or ACT results, college transcript(s), and the Dean's Recommendation Form. Applyingfor thefirst time. Transfer students should submit an application for admission, the final secondary- school transcript, SAT and/or ACT results, college transcript (s), and the Dean's Transfer Recommendation Form. Transfer ofcredits. Transfer credits are granted provisionally for individual coiuses passed with a C or better at approved institutions, provided that these courses fit reasonably well into the Gettysburg College curriculum. During the first semester, transfer students must review the graduation requirements with their academic advisor or the registrar. Transfers are required to earn all additional credit at Gettysburg College or through a regtilar College-approved program of off-campus study. In order to complete the transfer of course credits, transfer students are required to complete one year of satisfactory work at Gettysburg College. All transfer students must satisfy the course requirements in their major area of interest. Admission as a Guest Student A high school graduate, not a candidate for a degree, may apply for admission as a nonmatri-culated student. Normally, such a student may enroll in a maximum of two courses. Permission to take more than two courses must be secured from the Academic Standing Committee. Taking courses as a guest student requires permission of the instructors of the courses involved, as well as filing an application for guest student status with the admissions office. A guest student who may later wish to become a candidate for a degree miBt submit an application under regular admission procedures. Guest students have the same classroom duties and privileges as regular full-time students, but no promise is made in advance that the guest student will be admitted as a candidate for degree. STATISTICAL SUMMARY Students in college 2004 Full-Time Enrollment Fall Semester M W Total Senior 271 313 584 Junior 289 330 619 Sophomore 313 346 659 First Year 355 365 720 1,228 1,354 2,582 The above enrollment includes 163 students who were studying off campus. In addition, 1 1 students were enrolled part-time for a degree. Geograpliic Distribution Matriculated Students 2004 Fall Semester (includes all students) Number of Students Percent Pennsylvania 749 28.4 NewJersey 474 18.0 New York 339 12.9 Marviand 336 12.7 Connecdcut 187 7.1 Massachusetts 149 5.6 Virginia 61 2.3 Maine 46 1.7 New Hampshire 30 1.1 29 Other States or Territories 215 8.3 International (32 countries) 48 1.9 2,634

John W Lockwood - One of the best experts on this subject based on the ideXlab platform.

  • A NEW ARCHITECTURE PERFORMS CONTENT SCANNING OF TCP FLOWS IN HIGH- SPEED NETWORKS. COMBINING A TCP PROCESSING ENGINE, A PER-FLOW STATE STORE, AND A CONTENT-SCANNING ENGINE, THIS ARCHITECTURE PERMITS COMPLETE PAYLOAD INSPECTIONS ON 8 MILLION TCP FLOWS AT 2
    2020
    Co-Authors: David V Schuehler, James Moscola, John W Lockwood
    Abstract:

    The Transmission Control Protocol is the workhorse protocol of the Internet. Most of the data passing through the Internet transits the network using TCP layered atop the Internet Protocol (IP). Monitoring, capturing, filtering, and blocking traffic on highspeed Internet links requires the ability to directly process TCP packets in hardware. Because TCP is a stream-oriented protocol that operates above an unreliable datagram network, there are complexities in reconstructing the underlying data flow. High-speed network intrusion detection and prevention systems guard against several types of threats (see the "Related work" sidebar). When used in backbone networks, these content-scanning systems must not inhibit network throughput. Gilder's law predicts that the need for bandwidth will grow at least three times as fast as computing power. 1 As the gap between network bandwidth and computing power widens, improved microelectronic architectures are needed to monitor and filter network traffic without limiting throughput. To address these issues, we've designed a hardwarebased TCP/IP content-processing system that supports content scanning and flow blocking for millions of flows at gigabit line rates. TCP splitter The TCP splitter 2 technology was previously developed to monitor TCP data streams, sending a consistent byte stream of data to a client application for every TCP data flow passing through the circuit. The TCP splitter accomplishes this task by tracking the TCP sequence number along with the current flow state. Out-of-order packets are dropped to ensure that the client application receives the full TCP data stream without the need for large stream reassembly buffers. Dropping packets to maintain an ordered packet flow throughout the network can adversely affect the network's overall throughput. Jaiswal et al. analyzed out-of-sequence packets in tier-1 IP backbones. 3 They noted that Approximately 95 Percent of all TCP packets on Internet backbone links were in proper sequence. Network-induced packet reordering accounted for a small fraction of out-of-sequence packets, with most resulting from retransmissions due to data loss. More than 86 Percent of all observed TCP flows contained no out-of-sequence packets. Earlier A suite of layered protocol wrappers processes network and transport protocols in reconfigurable hardware. 5 The wrappers include an asynchronous transfer mode cell wrapper, an ATM adaptation layer type 5 (AAL5) frame wrapper, and an IP wrapper. 63 JANUARY-FEBRUARY 2004 By their very nature, intrusion detection systems (IDSs) and intrusion prevention systems must perform deep packet inspections on all traffic traversing the network. This task is difficult when data rates are high and the system must track many simultaneous flows. Software IDS solutions, such as Snort, 1 work well only when aggregate bandwidth rates are low. Implementing an external monitor that can track a Transmission Control Protocol (TCP) connection state is difficult. Bhargavan et al. discuss the complexities associated with tracking various properties of a protocol using language recognition techniques. 2 General solutions to this problem can vary greatly. Monitoring and reassembling flows-tasks required for an IDS-become even more complicated by direct attempts to evade detection. Handley et al. expound on this topic. 3 One such technique for evading detection would be to modify an end-system protocol stack such that TCP retransmissions contain different content than original data transmissions. A recently developed passive monitoring system can capture and accurately time stamp packets at data rates of up to OC-48 (2.5 Gbps). 4 Highly accurate time stamps correlate data captured by multiple monitoring systems in a wide area network. Optical splitters deliver a copy of the network traffic to the monitoring station. The system stores the first 44 bytes of each packet and the analysis of the captured data occurs out of band. Network World Fusion tested six commercially available gigabit IDSs by sending 28 attacks along with 970 Mbps of background traffic. 5 After system tuning, only one system detected all 28 of their attacks while processing data on a gigabit Ethernet link. In general, software-based systems are incapable of matching regular expressions at gigabit rates. Previous work also exists in the area of string matching on field-programmable gate arrays. Sidhu and Prasanna were primarily concerned with minimizing the time and space required to construct nondeterministic finite automatons (NFAs). 6 They run their NFA construction algorithm in hardware instead of software. To perform string matching, Hutchings, Franklin, and Carver followed with an analysis of this approach for the large set of regular expressions found in a Snort database. Related work These wrappers provide lower-layer protocol processing for our TCP architecture. Content-scanning engine The content-scanning engine can scan the payload of packets for a set of regular expressions. 6 To do so, this hardware module employs a set of deterministic finite automata, each searching in parallel for one of the targeted regular expressions. Upon matching a network data packet's payload with any of these regular expressions, the content-scanning engine can either let the data pass or drop the packet. This engine can also send an alert message to a log server when it detects a match in a packet. The alert message contains the matching packet's source and destination addresses along with a list of regular expressions found in the packet. The content-scanning engine, when implemented with four parallel search engines, provides a throughput of 2.5 Gbps. TCP-based content-scanning engine The new TCP-based content-scanning engine integrates and extends the capabilities of the TCP splitter and the old content-scanning engine. Design requirements A hashing algorithm that produces an even distribution across all hash buckets is important to the circuit's overall efficiency. We performed initial analysis of the flow-classification hashing algorithm for this system against packet traces available from the National Laboratory for Applied Network Research. With 26,452 flow identifiers hashed into a table of 8 million entries, a hash collision occurred in less than 0.3 Percent of the flows. We've added features to the TCP processing circuit to support the following services: • Flow blocking. This will let the system block a flow at a particular byte offset within the TCP data stream. • Flow unblocking. The system can reenable a previously disabled flow so that data for a particular flow can once again pass through the circuit. • Flow termination. This mechanism will shut down a selected flow by generating a TCP FIN (finish) packet. • Flow modification. We will provide the ability to sanitize selected data contained within a TCP stream. Flow state store To support millions of TCP flows, the TCP processing engine uses one 512-Mbyte, offchip, synchronous dynamic random access memory (SDRAM) module. The interface to this module has a 64-bit-wide data path and supports a burst length of eight memory operations. By matching our per-flow memory requirements with the burst width of the memory module, we can optimize use of memory bandwidth. Storing 64 bytes of state information for each flow lets the memory interface match the amount of per-flow state information with the amount of data in a burst transfer to memory. This configuration supports 8 million simultaneous flows. Assuming $50 as the purchase price for a 512-Mbyte SDRAM memory module, the cost to store context for 8 million flows is only 0.000625 cents per flow, or 1,600 flows per penny. Of the 64 bytes of data stored for each flow, the TCP processing engine uses 32 bytes to maintain flow state and memory management overhead. The additional 32 bytes of state store for each flow can hold the application-specific data for each flow context. The hash algorithm contained within the TCP processing engine hashes the source and destination IP addresses and TCP ports into a 22-bit value. This hash value serves as a direct index to the first entry in a hash bucket. The record's format lets the hash Figure 2. Flow state record for one entry, for a given flow. Each box represents 32 bits; two adjacent boxes collectively represent 64 bits, which the state store manager can read from SDRAM in one clock cycle. For example, the hash value is located at bits 31 to 0, and the flow ID at bits 63 to 32, of the first memory location. Because the memory device supports burst read and write operations, the state store manager retrieves all data (8 rows, 64 bits each) in a single memory operation. The state store manager maintains one of these records for every flow that the content-scanning engine processes. tion for multiple flows that hash to the same bucket. To ensure that the system can maintain real-time behavior, we constrain the number of link traversals to a constant value. The state store manager can cache state information using on-chip block RAM memory. This provides faster access to state information for the most recently accessed flows. A writeback cache design improves performance. Stream-based content scanning The content-scanning engine processes TCP data streams from the TCP processing engine, which lets the content-scanning engine match data that spans across multiple packets. The content-scanning engine must perform regular-expression-based scans on many active TCP flows. To process interleaved flows, it must perform a context switch to save and restore perflow context information. When a packet reaches the content-scanning engine through some flow, the content-scanning engine must restore the last known matching state for that flow before starting the matching operation on that packet. When it has finished processing the packet, the content-scanning engine must save the flow's new matching state by using the TCP processing circuit's state store resources. Each content-scanning engine processes data one byte at a time. The TCP processing circuit uses a 4-byte-wide data path, so the contentscanning engine must perform a 4-to-1 slowdown when processing packet data. Having four content-scanning engines in parallel and processing four flows concurrently, as TCP processing The architecture receives data through the IP wrappers. 3 As the left side of • a first-in, first-out (FIFO) frame buffer, which stores the packet; • a checksum engine, which validates the TCP checksum; and • a flow classifier, which computes a hash value for the packet. The flow classification hash value is passed to the state store manager, which retrieves the state information associated with the particular flow. Results are written to a control FIFO buffer, and the state store is updated with the current state of the flow. An output state machine reads data from the frame and control FIFO buffers and passes it to the packet-routing engine. Most traffic flows through the content-scanning engines, which scan the data. Packet retransmissions bypass these engines and go directly to the flowblocking module. Data returning from the content-scanning engines also goes to the flow-blocking module. This stage updates the per-flow state store with the latest application-specific state information. If a content-scanning engine has enabled blocking for a flow, the flow-blocking module now enforces it. This module compares the packet's sequence number with those sequence numbers for which flow blocking should take place. If the packet meets the blocking criteria, the flow-blocking module drops it from the network. Any remaining packets go to the outbound protocol wrapper. The state store manager is responsible for processing requests to read and write flow state records. It also handles all interactions with SDRAM memory, and it caches recently accessed flow state information. The SDRAM controller exposes three memory-access interfaces: a read-write, a write only, and a read only. The controller prioritizes requests in that order, with the read-write interface having the highest priority. In a worst-case scenario in which there's no more than one entry per hash bucket, each packet requires a total of two read and two write operations to the SDRAM: • an 8-word read to retrieve flow state, • an 8-word write to initialize a new flow record, • a 4-word read to retrieve flow-blocking information, and • a 5-word write to update application-specific flow state and blocking information. Memory accesses aren't necessary for TCP acknowledgment packets containing no data. Analysis indicates that all read and write operations can occur during packet processing if the average TCP packet contains more than 120 bytes of data. If the TCP packets contain less than this amount, there might not be enough time to complete all memory operations during packet processing. In that case

David V Schuehler - One of the best experts on this subject based on the ideXlab platform.

  • A NEW ARCHITECTURE PERFORMS CONTENT SCANNING OF TCP FLOWS IN HIGH- SPEED NETWORKS. COMBINING A TCP PROCESSING ENGINE, A PER-FLOW STATE STORE, AND A CONTENT-SCANNING ENGINE, THIS ARCHITECTURE PERMITS COMPLETE PAYLOAD INSPECTIONS ON 8 MILLION TCP FLOWS AT 2
    2020
    Co-Authors: David V Schuehler, James Moscola, John W Lockwood
    Abstract:

    The Transmission Control Protocol is the workhorse protocol of the Internet. Most of the data passing through the Internet transits the network using TCP layered atop the Internet Protocol (IP). Monitoring, capturing, filtering, and blocking traffic on highspeed Internet links requires the ability to directly process TCP packets in hardware. Because TCP is a stream-oriented protocol that operates above an unreliable datagram network, there are complexities in reconstructing the underlying data flow. High-speed network intrusion detection and prevention systems guard against several types of threats (see the "Related work" sidebar). When used in backbone networks, these content-scanning systems must not inhibit network throughput. Gilder's law predicts that the need for bandwidth will grow at least three times as fast as computing power. 1 As the gap between network bandwidth and computing power widens, improved microelectronic architectures are needed to monitor and filter network traffic without limiting throughput. To address these issues, we've designed a hardwarebased TCP/IP content-processing system that supports content scanning and flow blocking for millions of flows at gigabit line rates. TCP splitter The TCP splitter 2 technology was previously developed to monitor TCP data streams, sending a consistent byte stream of data to a client application for every TCP data flow passing through the circuit. The TCP splitter accomplishes this task by tracking the TCP sequence number along with the current flow state. Out-of-order packets are dropped to ensure that the client application receives the full TCP data stream without the need for large stream reassembly buffers. Dropping packets to maintain an ordered packet flow throughout the network can adversely affect the network's overall throughput. Jaiswal et al. analyzed out-of-sequence packets in tier-1 IP backbones. 3 They noted that Approximately 95 Percent of all TCP packets on Internet backbone links were in proper sequence. Network-induced packet reordering accounted for a small fraction of out-of-sequence packets, with most resulting from retransmissions due to data loss. More than 86 Percent of all observed TCP flows contained no out-of-sequence packets. Earlier A suite of layered protocol wrappers processes network and transport protocols in reconfigurable hardware. 5 The wrappers include an asynchronous transfer mode cell wrapper, an ATM adaptation layer type 5 (AAL5) frame wrapper, and an IP wrapper. 63 JANUARY-FEBRUARY 2004 By their very nature, intrusion detection systems (IDSs) and intrusion prevention systems must perform deep packet inspections on all traffic traversing the network. This task is difficult when data rates are high and the system must track many simultaneous flows. Software IDS solutions, such as Snort, 1 work well only when aggregate bandwidth rates are low. Implementing an external monitor that can track a Transmission Control Protocol (TCP) connection state is difficult. Bhargavan et al. discuss the complexities associated with tracking various properties of a protocol using language recognition techniques. 2 General solutions to this problem can vary greatly. Monitoring and reassembling flows-tasks required for an IDS-become even more complicated by direct attempts to evade detection. Handley et al. expound on this topic. 3 One such technique for evading detection would be to modify an end-system protocol stack such that TCP retransmissions contain different content than original data transmissions. A recently developed passive monitoring system can capture and accurately time stamp packets at data rates of up to OC-48 (2.5 Gbps). 4 Highly accurate time stamps correlate data captured by multiple monitoring systems in a wide area network. Optical splitters deliver a copy of the network traffic to the monitoring station. The system stores the first 44 bytes of each packet and the analysis of the captured data occurs out of band. Network World Fusion tested six commercially available gigabit IDSs by sending 28 attacks along with 970 Mbps of background traffic. 5 After system tuning, only one system detected all 28 of their attacks while processing data on a gigabit Ethernet link. In general, software-based systems are incapable of matching regular expressions at gigabit rates. Previous work also exists in the area of string matching on field-programmable gate arrays. Sidhu and Prasanna were primarily concerned with minimizing the time and space required to construct nondeterministic finite automatons (NFAs). 6 They run their NFA construction algorithm in hardware instead of software. To perform string matching, Hutchings, Franklin, and Carver followed with an analysis of this approach for the large set of regular expressions found in a Snort database. Related work These wrappers provide lower-layer protocol processing for our TCP architecture. Content-scanning engine The content-scanning engine can scan the payload of packets for a set of regular expressions. 6 To do so, this hardware module employs a set of deterministic finite automata, each searching in parallel for one of the targeted regular expressions. Upon matching a network data packet's payload with any of these regular expressions, the content-scanning engine can either let the data pass or drop the packet. This engine can also send an alert message to a log server when it detects a match in a packet. The alert message contains the matching packet's source and destination addresses along with a list of regular expressions found in the packet. The content-scanning engine, when implemented with four parallel search engines, provides a throughput of 2.5 Gbps. TCP-based content-scanning engine The new TCP-based content-scanning engine integrates and extends the capabilities of the TCP splitter and the old content-scanning engine. Design requirements A hashing algorithm that produces an even distribution across all hash buckets is important to the circuit's overall efficiency. We performed initial analysis of the flow-classification hashing algorithm for this system against packet traces available from the National Laboratory for Applied Network Research. With 26,452 flow identifiers hashed into a table of 8 million entries, a hash collision occurred in less than 0.3 Percent of the flows. We've added features to the TCP processing circuit to support the following services: • Flow blocking. This will let the system block a flow at a particular byte offset within the TCP data stream. • Flow unblocking. The system can reenable a previously disabled flow so that data for a particular flow can once again pass through the circuit. • Flow termination. This mechanism will shut down a selected flow by generating a TCP FIN (finish) packet. • Flow modification. We will provide the ability to sanitize selected data contained within a TCP stream. Flow state store To support millions of TCP flows, the TCP processing engine uses one 512-Mbyte, offchip, synchronous dynamic random access memory (SDRAM) module. The interface to this module has a 64-bit-wide data path and supports a burst length of eight memory operations. By matching our per-flow memory requirements with the burst width of the memory module, we can optimize use of memory bandwidth. Storing 64 bytes of state information for each flow lets the memory interface match the amount of per-flow state information with the amount of data in a burst transfer to memory. This configuration supports 8 million simultaneous flows. Assuming $50 as the purchase price for a 512-Mbyte SDRAM memory module, the cost to store context for 8 million flows is only 0.000625 cents per flow, or 1,600 flows per penny. Of the 64 bytes of data stored for each flow, the TCP processing engine uses 32 bytes to maintain flow state and memory management overhead. The additional 32 bytes of state store for each flow can hold the application-specific data for each flow context. The hash algorithm contained within the TCP processing engine hashes the source and destination IP addresses and TCP ports into a 22-bit value. This hash value serves as a direct index to the first entry in a hash bucket. The record's format lets the hash Figure 2. Flow state record for one entry, for a given flow. Each box represents 32 bits; two adjacent boxes collectively represent 64 bits, which the state store manager can read from SDRAM in one clock cycle. For example, the hash value is located at bits 31 to 0, and the flow ID at bits 63 to 32, of the first memory location. Because the memory device supports burst read and write operations, the state store manager retrieves all data (8 rows, 64 bits each) in a single memory operation. The state store manager maintains one of these records for every flow that the content-scanning engine processes. tion for multiple flows that hash to the same bucket. To ensure that the system can maintain real-time behavior, we constrain the number of link traversals to a constant value. The state store manager can cache state information using on-chip block RAM memory. This provides faster access to state information for the most recently accessed flows. A writeback cache design improves performance. Stream-based content scanning The content-scanning engine processes TCP data streams from the TCP processing engine, which lets the content-scanning engine match data that spans across multiple packets. The content-scanning engine must perform regular-expression-based scans on many active TCP flows. To process interleaved flows, it must perform a context switch to save and restore perflow context information. When a packet reaches the content-scanning engine through some flow, the content-scanning engine must restore the last known matching state for that flow before starting the matching operation on that packet. When it has finished processing the packet, the content-scanning engine must save the flow's new matching state by using the TCP processing circuit's state store resources. Each content-scanning engine processes data one byte at a time. The TCP processing circuit uses a 4-byte-wide data path, so the contentscanning engine must perform a 4-to-1 slowdown when processing packet data. Having four content-scanning engines in parallel and processing four flows concurrently, as TCP processing The architecture receives data through the IP wrappers. 3 As the left side of • a first-in, first-out (FIFO) frame buffer, which stores the packet; • a checksum engine, which validates the TCP checksum; and • a flow classifier, which computes a hash value for the packet. The flow classification hash value is passed to the state store manager, which retrieves the state information associated with the particular flow. Results are written to a control FIFO buffer, and the state store is updated with the current state of the flow. An output state machine reads data from the frame and control FIFO buffers and passes it to the packet-routing engine. Most traffic flows through the content-scanning engines, which scan the data. Packet retransmissions bypass these engines and go directly to the flowblocking module. Data returning from the content-scanning engines also goes to the flow-blocking module. This stage updates the per-flow state store with the latest application-specific state information. If a content-scanning engine has enabled blocking for a flow, the flow-blocking module now enforces it. This module compares the packet's sequence number with those sequence numbers for which flow blocking should take place. If the packet meets the blocking criteria, the flow-blocking module drops it from the network. Any remaining packets go to the outbound protocol wrapper. The state store manager is responsible for processing requests to read and write flow state records. It also handles all interactions with SDRAM memory, and it caches recently accessed flow state information. The SDRAM controller exposes three memory-access interfaces: a read-write, a write only, and a read only. The controller prioritizes requests in that order, with the read-write interface having the highest priority. In a worst-case scenario in which there's no more than one entry per hash bucket, each packet requires a total of two read and two write operations to the SDRAM: • an 8-word read to retrieve flow state, • an 8-word write to initialize a new flow record, • a 4-word read to retrieve flow-blocking information, and • a 5-word write to update application-specific flow state and blocking information. Memory accesses aren't necessary for TCP acknowledgment packets containing no data. Analysis indicates that all read and write operations can occur during packet processing if the average TCP packet contains more than 120 bytes of data. If the TCP packets contain less than this amount, there might not be enough time to complete all memory operations during packet processing. In that case

James Moscola - One of the best experts on this subject based on the ideXlab platform.

  • A NEW ARCHITECTURE PERFORMS CONTENT SCANNING OF TCP FLOWS IN HIGH- SPEED NETWORKS. COMBINING A TCP PROCESSING ENGINE, A PER-FLOW STATE STORE, AND A CONTENT-SCANNING ENGINE, THIS ARCHITECTURE PERMITS COMPLETE PAYLOAD INSPECTIONS ON 8 MILLION TCP FLOWS AT 2
    2020
    Co-Authors: David V Schuehler, James Moscola, John W Lockwood
    Abstract:

    The Transmission Control Protocol is the workhorse protocol of the Internet. Most of the data passing through the Internet transits the network using TCP layered atop the Internet Protocol (IP). Monitoring, capturing, filtering, and blocking traffic on highspeed Internet links requires the ability to directly process TCP packets in hardware. Because TCP is a stream-oriented protocol that operates above an unreliable datagram network, there are complexities in reconstructing the underlying data flow. High-speed network intrusion detection and prevention systems guard against several types of threats (see the "Related work" sidebar). When used in backbone networks, these content-scanning systems must not inhibit network throughput. Gilder's law predicts that the need for bandwidth will grow at least three times as fast as computing power. 1 As the gap between network bandwidth and computing power widens, improved microelectronic architectures are needed to monitor and filter network traffic without limiting throughput. To address these issues, we've designed a hardwarebased TCP/IP content-processing system that supports content scanning and flow blocking for millions of flows at gigabit line rates. TCP splitter The TCP splitter 2 technology was previously developed to monitor TCP data streams, sending a consistent byte stream of data to a client application for every TCP data flow passing through the circuit. The TCP splitter accomplishes this task by tracking the TCP sequence number along with the current flow state. Out-of-order packets are dropped to ensure that the client application receives the full TCP data stream without the need for large stream reassembly buffers. Dropping packets to maintain an ordered packet flow throughout the network can adversely affect the network's overall throughput. Jaiswal et al. analyzed out-of-sequence packets in tier-1 IP backbones. 3 They noted that Approximately 95 Percent of all TCP packets on Internet backbone links were in proper sequence. Network-induced packet reordering accounted for a small fraction of out-of-sequence packets, with most resulting from retransmissions due to data loss. More than 86 Percent of all observed TCP flows contained no out-of-sequence packets. Earlier A suite of layered protocol wrappers processes network and transport protocols in reconfigurable hardware. 5 The wrappers include an asynchronous transfer mode cell wrapper, an ATM adaptation layer type 5 (AAL5) frame wrapper, and an IP wrapper. 63 JANUARY-FEBRUARY 2004 By their very nature, intrusion detection systems (IDSs) and intrusion prevention systems must perform deep packet inspections on all traffic traversing the network. This task is difficult when data rates are high and the system must track many simultaneous flows. Software IDS solutions, such as Snort, 1 work well only when aggregate bandwidth rates are low. Implementing an external monitor that can track a Transmission Control Protocol (TCP) connection state is difficult. Bhargavan et al. discuss the complexities associated with tracking various properties of a protocol using language recognition techniques. 2 General solutions to this problem can vary greatly. Monitoring and reassembling flows-tasks required for an IDS-become even more complicated by direct attempts to evade detection. Handley et al. expound on this topic. 3 One such technique for evading detection would be to modify an end-system protocol stack such that TCP retransmissions contain different content than original data transmissions. A recently developed passive monitoring system can capture and accurately time stamp packets at data rates of up to OC-48 (2.5 Gbps). 4 Highly accurate time stamps correlate data captured by multiple monitoring systems in a wide area network. Optical splitters deliver a copy of the network traffic to the monitoring station. The system stores the first 44 bytes of each packet and the analysis of the captured data occurs out of band. Network World Fusion tested six commercially available gigabit IDSs by sending 28 attacks along with 970 Mbps of background traffic. 5 After system tuning, only one system detected all 28 of their attacks while processing data on a gigabit Ethernet link. In general, software-based systems are incapable of matching regular expressions at gigabit rates. Previous work also exists in the area of string matching on field-programmable gate arrays. Sidhu and Prasanna were primarily concerned with minimizing the time and space required to construct nondeterministic finite automatons (NFAs). 6 They run their NFA construction algorithm in hardware instead of software. To perform string matching, Hutchings, Franklin, and Carver followed with an analysis of this approach for the large set of regular expressions found in a Snort database. Related work These wrappers provide lower-layer protocol processing for our TCP architecture. Content-scanning engine The content-scanning engine can scan the payload of packets for a set of regular expressions. 6 To do so, this hardware module employs a set of deterministic finite automata, each searching in parallel for one of the targeted regular expressions. Upon matching a network data packet's payload with any of these regular expressions, the content-scanning engine can either let the data pass or drop the packet. This engine can also send an alert message to a log server when it detects a match in a packet. The alert message contains the matching packet's source and destination addresses along with a list of regular expressions found in the packet. The content-scanning engine, when implemented with four parallel search engines, provides a throughput of 2.5 Gbps. TCP-based content-scanning engine The new TCP-based content-scanning engine integrates and extends the capabilities of the TCP splitter and the old content-scanning engine. Design requirements A hashing algorithm that produces an even distribution across all hash buckets is important to the circuit's overall efficiency. We performed initial analysis of the flow-classification hashing algorithm for this system against packet traces available from the National Laboratory for Applied Network Research. With 26,452 flow identifiers hashed into a table of 8 million entries, a hash collision occurred in less than 0.3 Percent of the flows. We've added features to the TCP processing circuit to support the following services: • Flow blocking. This will let the system block a flow at a particular byte offset within the TCP data stream. • Flow unblocking. The system can reenable a previously disabled flow so that data for a particular flow can once again pass through the circuit. • Flow termination. This mechanism will shut down a selected flow by generating a TCP FIN (finish) packet. • Flow modification. We will provide the ability to sanitize selected data contained within a TCP stream. Flow state store To support millions of TCP flows, the TCP processing engine uses one 512-Mbyte, offchip, synchronous dynamic random access memory (SDRAM) module. The interface to this module has a 64-bit-wide data path and supports a burst length of eight memory operations. By matching our per-flow memory requirements with the burst width of the memory module, we can optimize use of memory bandwidth. Storing 64 bytes of state information for each flow lets the memory interface match the amount of per-flow state information with the amount of data in a burst transfer to memory. This configuration supports 8 million simultaneous flows. Assuming $50 as the purchase price for a 512-Mbyte SDRAM memory module, the cost to store context for 8 million flows is only 0.000625 cents per flow, or 1,600 flows per penny. Of the 64 bytes of data stored for each flow, the TCP processing engine uses 32 bytes to maintain flow state and memory management overhead. The additional 32 bytes of state store for each flow can hold the application-specific data for each flow context. The hash algorithm contained within the TCP processing engine hashes the source and destination IP addresses and TCP ports into a 22-bit value. This hash value serves as a direct index to the first entry in a hash bucket. The record's format lets the hash Figure 2. Flow state record for one entry, for a given flow. Each box represents 32 bits; two adjacent boxes collectively represent 64 bits, which the state store manager can read from SDRAM in one clock cycle. For example, the hash value is located at bits 31 to 0, and the flow ID at bits 63 to 32, of the first memory location. Because the memory device supports burst read and write operations, the state store manager retrieves all data (8 rows, 64 bits each) in a single memory operation. The state store manager maintains one of these records for every flow that the content-scanning engine processes. tion for multiple flows that hash to the same bucket. To ensure that the system can maintain real-time behavior, we constrain the number of link traversals to a constant value. The state store manager can cache state information using on-chip block RAM memory. This provides faster access to state information for the most recently accessed flows. A writeback cache design improves performance. Stream-based content scanning The content-scanning engine processes TCP data streams from the TCP processing engine, which lets the content-scanning engine match data that spans across multiple packets. The content-scanning engine must perform regular-expression-based scans on many active TCP flows. To process interleaved flows, it must perform a context switch to save and restore perflow context information. When a packet reaches the content-scanning engine through some flow, the content-scanning engine must restore the last known matching state for that flow before starting the matching operation on that packet. When it has finished processing the packet, the content-scanning engine must save the flow's new matching state by using the TCP processing circuit's state store resources. Each content-scanning engine processes data one byte at a time. The TCP processing circuit uses a 4-byte-wide data path, so the contentscanning engine must perform a 4-to-1 slowdown when processing packet data. Having four content-scanning engines in parallel and processing four flows concurrently, as TCP processing The architecture receives data through the IP wrappers. 3 As the left side of • a first-in, first-out (FIFO) frame buffer, which stores the packet; • a checksum engine, which validates the TCP checksum; and • a flow classifier, which computes a hash value for the packet. The flow classification hash value is passed to the state store manager, which retrieves the state information associated with the particular flow. Results are written to a control FIFO buffer, and the state store is updated with the current state of the flow. An output state machine reads data from the frame and control FIFO buffers and passes it to the packet-routing engine. Most traffic flows through the content-scanning engines, which scan the data. Packet retransmissions bypass these engines and go directly to the flowblocking module. Data returning from the content-scanning engines also goes to the flow-blocking module. This stage updates the per-flow state store with the latest application-specific state information. If a content-scanning engine has enabled blocking for a flow, the flow-blocking module now enforces it. This module compares the packet's sequence number with those sequence numbers for which flow blocking should take place. If the packet meets the blocking criteria, the flow-blocking module drops it from the network. Any remaining packets go to the outbound protocol wrapper. The state store manager is responsible for processing requests to read and write flow state records. It also handles all interactions with SDRAM memory, and it caches recently accessed flow state information. The SDRAM controller exposes three memory-access interfaces: a read-write, a write only, and a read only. The controller prioritizes requests in that order, with the read-write interface having the highest priority. In a worst-case scenario in which there's no more than one entry per hash bucket, each packet requires a total of two read and two write operations to the SDRAM: • an 8-word read to retrieve flow state, • an 8-word write to initialize a new flow record, • a 4-word read to retrieve flow-blocking information, and • a 5-word write to update application-specific flow state and blocking information. Memory accesses aren't necessary for TCP acknowledgment packets containing no data. Analysis indicates that all read and write operations can occur during packet processing if the average TCP packet contains more than 120 bytes of data. If the TCP packets contain less than this amount, there might not be enough time to complete all memory operations during packet processing. In that case

Qun G Jiao - One of the best experts on this subject based on the ideXlab platform.

  • i ll go to the library later the relationship between academic procrastination and library anxiety
    College & Research Libraries, 2000
    Co-Authors: Anthony J Onwuegbuzie, Qun G Jiao
    Abstract:

    Approximately 95 Percent of college students procrastinate on academic tasks such as writing term papers, studying for examinations, and keeping up with weekly reading assignments. At the graduate level, an estimated 60 Percent of students procrastinate on academic tasks. Academic procrastination stems primarily from fear of failure and task aversiveness. It has been theorized, though not tested empirically, that highly anxious graduate students typically procrastinate while engaged in library-related tasks. This study investigated the relationship between academic procrastination and library anxiety at the graduate level. Participants included 135 graduate students enrolled in three sections of a required introductory-level educational research course. Findings revealed that, overall, academic procrastination was significantly positively related to the following dimensions of library anxiety: affective barriers, comfort with the library, and mechanical barriers. A canonical correlation analysis revealed that academic procrastination resulting from both fear of failure and task aversiveness was related significantly to barriers with staff, affective barriers, comfort with the library, and knowledge of the library. Implications for library anxiety reduction as a procrastination intervention are discussed.