The Experts below are selected from a list of 8058 Experts worldwide ranked by ideXlab platform

Andrew W. Moore - One of the best experts on this subject based on the ideXlab platform.

  • hypafilter enhanced hybrid packet filtering using hardware assisted classification and header space analysis
    IEEE ACM Transactions on Networking, 2017
    Co-Authors: Andreas Fiessler, Claas Lorenz, Sven Hager, Bjorn Scheuermann, Andrew W. Moore
    Abstract:

    Firewalls, key components for Secured Network infrastructures, are faced with two different kinds of challenges: first, they must be fast enough to classify Network packets at line speed, and second, their packet processing capabilities should be versatile in order to support complex filtering policies. Unfortunately, most existing classification systems do not qualify equally well for both requirements: systems built on special-purpose hardware are fast, but limited in their filtering functionality. In contrast, software filters provide powerful matching semantics, but struggle to meet line speed. This motivates the combination of parallel, yet complexity-limited specialized circuitry with a slower, but versatile software firewall. The key challenge in such a design arises from the dependencies between classification rules due to their relative priorities within the rule set: complex rules requiring software-based processing may be interleaved at arbitrary positions between those where hardware processing is feasible. Therefore, we discuss approaches for partitioning and transforming rule sets for hybrid packet processing. As a result, we propose HyPaFilter+, a hybrid classification system consisting of an FPGA-based hardware matcher and a Linux netfilter firewall, which provides a simple, yet effective hardware/software packet shunting algorithm. Our evaluation shows up to 30-fold throughput gains over software packet processing.

Moore Andrew - One of the best experts on this subject based on the ideXlab platform.

  • HyPaFilter+: Enhanced Hybrid Packet Filtering using Hardware Assisted Classification and Header Space Analysis
    'Organisation for Economic Co-Operation and Development (OECD)', 2017
    Co-Authors: Fiessler A, Lorenz C, Hager S, Scheuermann B, Moore Andrew
    Abstract:

    Firewalls, key components for Secured Network in- frastructures, are faced with two different kinds of challenges: first, they must be fast enough to classify Network packets at line speed, second, their packet processing capabilities should be versatile in order to support complex filtering policies. Unfortu- nately, most existing classification systems do not qualify equally well for both requirements: systems built on special-purpose hardware are fast, but limited in their filtering functionality. In contrast, software filters provide powerful matching semantics, but struggle to meet line speed. This motivates the combination of parallel, yet complexity-limited specialized circuitry with a slower, but versatile software firewall. The key challenge in such a design arises from the dependencies between classification rules due to their relative priorities within the rule set: complex rules requiring software-based processing may be interleaved at arbitrary positions between those where hardware processing is feasible. We therefore discuss approaches for partitioning and transforming rule sets for hybrid packet processing. As a result we propose HyPaFilter+, a hybrid classification system consisting of an FPGA-based hardware matcher and a Linux netfilter firewall, which provides a simple, yet effective hardware/software packet shunting algorithm. Our evaluation shows up to 30-fold throughput gains over software packet processing.We would like to acknowledge the support of the German Federal Ministry for Economic Affairs and Energy and the German Federal Ministry of Education and Research. This work was, in part, supported by the EU Horizon 2020 SSICLOPS project (grant agreement 644866)

Antonio Jara - One of the best experts on this subject based on the ideXlab platform.

  • A Novel Distributed SDN-Secured Architecture for the IoT
    2016 International Conference on Distributed Computing in Sensor Systems (DCOSS), 2016
    Co-Authors: Carlos Gonzalez, Olivier Flauzac, Florent Nolot, Antonio Jara
    Abstract:

    Due to their rapid evolution, mobile devices demand for more dynamic and flexible Networking services. A major challenges of future mobile Networks is the increased mobile traffic. With the recent upcoming technologies of Network programmability like Software-Defined Network (SDN), it may be integrated to create a new communication platform for Internet of Things (IoT). In this work, we present how to determine the effectiveness of an approach to build a new Secured Network architecture based on SDN and clusters. Our proposed scheme is a starting point for some experiments providing perspective over SDN deployment in a cluster environment. With this aim in mind, we suggest a routing protocol that manages routing tasks over Cluster-SDN. By using Network virtualization and OpenFlow technologies to generate virtual nodes, we simulate a prototype system controlled by SDN. With our testbed, we are able to manage 500 things. We can analyze every OpenFlow messages and we have discovered that with a particular flow, the things can exchange information unlike the routing principle.

Andreas Fiessler - One of the best experts on this subject based on the ideXlab platform.

  • hypafilter enhanced hybrid packet filtering using hardware assisted classification and header space analysis
    IEEE ACM Transactions on Networking, 2017
    Co-Authors: Andreas Fiessler, Claas Lorenz, Sven Hager, Bjorn Scheuermann, Andrew W. Moore
    Abstract:

    Firewalls, key components for Secured Network infrastructures, are faced with two different kinds of challenges: first, they must be fast enough to classify Network packets at line speed, and second, their packet processing capabilities should be versatile in order to support complex filtering policies. Unfortunately, most existing classification systems do not qualify equally well for both requirements: systems built on special-purpose hardware are fast, but limited in their filtering functionality. In contrast, software filters provide powerful matching semantics, but struggle to meet line speed. This motivates the combination of parallel, yet complexity-limited specialized circuitry with a slower, but versatile software firewall. The key challenge in such a design arises from the dependencies between classification rules due to their relative priorities within the rule set: complex rules requiring software-based processing may be interleaved at arbitrary positions between those where hardware processing is feasible. Therefore, we discuss approaches for partitioning and transforming rule sets for hybrid packet processing. As a result, we propose HyPaFilter+, a hybrid classification system consisting of an FPGA-based hardware matcher and a Linux netfilter firewall, which provides a simple, yet effective hardware/software packet shunting algorithm. Our evaluation shows up to 30-fold throughput gains over software packet processing.

Fiessler A - One of the best experts on this subject based on the ideXlab platform.

  • HyPaFilter+: Enhanced Hybrid Packet Filtering using Hardware Assisted Classification and Header Space Analysis
    'Organisation for Economic Co-Operation and Development (OECD)', 2017
    Co-Authors: Fiessler A, Lorenz C, Hager S, Scheuermann B, Moore Andrew
    Abstract:

    Firewalls, key components for Secured Network in- frastructures, are faced with two different kinds of challenges: first, they must be fast enough to classify Network packets at line speed, second, their packet processing capabilities should be versatile in order to support complex filtering policies. Unfortu- nately, most existing classification systems do not qualify equally well for both requirements: systems built on special-purpose hardware are fast, but limited in their filtering functionality. In contrast, software filters provide powerful matching semantics, but struggle to meet line speed. This motivates the combination of parallel, yet complexity-limited specialized circuitry with a slower, but versatile software firewall. The key challenge in such a design arises from the dependencies between classification rules due to their relative priorities within the rule set: complex rules requiring software-based processing may be interleaved at arbitrary positions between those where hardware processing is feasible. We therefore discuss approaches for partitioning and transforming rule sets for hybrid packet processing. As a result we propose HyPaFilter+, a hybrid classification system consisting of an FPGA-based hardware matcher and a Linux netfilter firewall, which provides a simple, yet effective hardware/software packet shunting algorithm. Our evaluation shows up to 30-fold throughput gains over software packet processing.We would like to acknowledge the support of the German Federal Ministry for Economic Affairs and Energy and the German Federal Ministry of Education and Research. This work was, in part, supported by the EU Horizon 2020 SSICLOPS project (grant agreement 644866)