The Experts below are selected from a list of 48 Experts worldwide ranked by ideXlab platform
Fraboul Christian - One of the best experts on this subject based on the ideXlab platform.
-
Extending Firewall Session Table to Accelerate NAT, QoS Classification and Routing
2009Co-Authors: Mostafa Mahmoud, Anas Abou El Kalam, Fraboul ChristianAbstract:security and QoS are the two most precious objectives for network systems to be attained. Unfortunately, they are in conflict, while QoS tries to minimize processing delay, strong security protection requires more processing time and cause Packet delay. This article is a step towards resolving this conflict by extending the firewall session table to accelerate NAT, QoS classification, and routing processing time while providing the same level of security protection. Index Terms ? Stateful Packet Filtering; firewall; session/state table; QoS; NAT; Routing
-
Extending Firewall Session Table to Accelerate NAT, QoS Classification and Routing
HAL CCSD, 2009Co-Authors: Mostafa Mahmoud, Abou El Kalam Anas, Fraboul ChristianAbstract:International audiencesecurity and QoS are the two most precious objectives for network systems to be attained. Unfortunately, they are in conflict, while QoS tries to minimize processing delay, strong security protection requires more processing time and cause Packet delay. This article is a step towards resolving this conflict by extending the firewall session table to accelerate NAT, QoS classification, and routing processing time while providing the same level of security protection. Index Terms — Stateful Packet Filtering; firewall; session/state table; QoS; NAT; Routing
G. Varghese - One of the best experts on this subject based on the ideXlab platform.
-
Fast and scalable conflict detection for Packet classifiers
2003Co-Authors: F. Baboescu, G. VargheseAbstract:Packet filters provide rules for classifying Packets based on header fields. High speed Packet classification has received much study. However, the twin problems of fast updates and fast conflict detection have not received much attention. A conflict occurs when two classifiers overlap, potentially creating ambiguity for Packets that match both filters. For example, if Rule 1 specifies that all Packets going to CNN be rate controlled and Rule 2specifies that all Packets coming from Walmart be given high priority, the rules conflict for traffic from Walmart to CNN. There has been prior work on efficient conflict detection for two-dimensional classifiers. However, the best known algorithm for conflict detection for general classifiers is the naive O(N²) algorithm of comparing each pair of rules for a conflict. In this paper, we describe an efficient and scalable conflict detection algorithm for the general case that is significantly faster. For example, for a database of 20 000 rules, our algorithm is 40 times faster than the naive implementation. Even without considering conflicts, our algorithm also provides a Packet classifier with fast updates and fast lookups that can be used for Stateful Packet Filtering
-
Fast and scalable conflict detection for Packet classifiers
10th IEEE International Conference on Network Protocols 2002. Proceedings., 2002Co-Authors: F. Baboescu, G. VargheseAbstract:Packet filters provide rules for classifying Packets based on header fields. High speed Packet classification has received much study. However, the twin problems of fast updates and fast conflict detection have not received much attention. A conflict occurs when two classifiers overlap, potentially creating ambiguity for Packets that match both filters. For example, if Rule 1 specifies that all Packets going to CNN be rate controlled and Rule 2 specifies that all Packets coming from Walmart be given high priority, the rules conflict for traffic from Walmart to CNN. There has been prior work on efficient conflict detection for two dimensional classifiers. However, the best known algorithm for conflict detection for general classifiers is the naive O(N/sup 2/) algorithm of comparing each pair of rules for a conflict. We describe an efficient and scalable conflict detection algorithm for the general case that is significantly faster. For example, for a database of 20,000 rules, our algorithm is 40 times faster than the naive implementation. Even without considering conflicts, our algorithm also provides a Packet classifier with fast updates and fast lookups that can be used for Stateful Packet Filtering.
Mostafa Mahmoud - One of the best experts on this subject based on the ideXlab platform.
-
Extending Firewall Session Table to Accelerate NAT, QoS Classification and Routing
2009Co-Authors: Mostafa Mahmoud, Anas Abou El Kalam, Fraboul ChristianAbstract:security and QoS are the two most precious objectives for network systems to be attained. Unfortunately, they are in conflict, while QoS tries to minimize processing delay, strong security protection requires more processing time and cause Packet delay. This article is a step towards resolving this conflict by extending the firewall session table to accelerate NAT, QoS classification, and routing processing time while providing the same level of security protection. Index Terms ? Stateful Packet Filtering; firewall; session/state table; QoS; NAT; Routing
-
Extending Firewall Session Table to Accelerate NAT, QoS Classification and Routing
HAL CCSD, 2009Co-Authors: Mostafa Mahmoud, Abou El Kalam Anas, Fraboul ChristianAbstract:International audiencesecurity and QoS are the two most precious objectives for network systems to be attained. Unfortunately, they are in conflict, while QoS tries to minimize processing delay, strong security protection requires more processing time and cause Packet delay. This article is a step towards resolving this conflict by extending the firewall session table to accelerate NAT, QoS classification, and routing processing time while providing the same level of security protection. Index Terms — Stateful Packet Filtering; firewall; session/state table; QoS; NAT; Routing
F. Baboescu - One of the best experts on this subject based on the ideXlab platform.
-
Fast and scalable conflict detection for Packet classifiers
2003Co-Authors: F. Baboescu, G. VargheseAbstract:Packet filters provide rules for classifying Packets based on header fields. High speed Packet classification has received much study. However, the twin problems of fast updates and fast conflict detection have not received much attention. A conflict occurs when two classifiers overlap, potentially creating ambiguity for Packets that match both filters. For example, if Rule 1 specifies that all Packets going to CNN be rate controlled and Rule 2specifies that all Packets coming from Walmart be given high priority, the rules conflict for traffic from Walmart to CNN. There has been prior work on efficient conflict detection for two-dimensional classifiers. However, the best known algorithm for conflict detection for general classifiers is the naive O(N²) algorithm of comparing each pair of rules for a conflict. In this paper, we describe an efficient and scalable conflict detection algorithm for the general case that is significantly faster. For example, for a database of 20 000 rules, our algorithm is 40 times faster than the naive implementation. Even without considering conflicts, our algorithm also provides a Packet classifier with fast updates and fast lookups that can be used for Stateful Packet Filtering
-
Fast and scalable conflict detection for Packet classifiers
10th IEEE International Conference on Network Protocols 2002. Proceedings., 2002Co-Authors: F. Baboescu, G. VargheseAbstract:Packet filters provide rules for classifying Packets based on header fields. High speed Packet classification has received much study. However, the twin problems of fast updates and fast conflict detection have not received much attention. A conflict occurs when two classifiers overlap, potentially creating ambiguity for Packets that match both filters. For example, if Rule 1 specifies that all Packets going to CNN be rate controlled and Rule 2 specifies that all Packets coming from Walmart be given high priority, the rules conflict for traffic from Walmart to CNN. There has been prior work on efficient conflict detection for two dimensional classifiers. However, the best known algorithm for conflict detection for general classifiers is the naive O(N/sup 2/) algorithm of comparing each pair of rules for a conflict. We describe an efficient and scalable conflict detection algorithm for the general case that is significantly faster. For example, for a database of 20,000 rules, our algorithm is 40 times faster than the naive implementation. Even without considering conflicts, our algorithm also provides a Packet classifier with fast updates and fast lookups that can be used for Stateful Packet Filtering.
Christian Fraboul - One of the best experts on this subject based on the ideXlab platform.
-
Egypt (2009)" Extending Firewall Session Table to Accelerate NAT, QoS Classification and Routing
2009Co-Authors: Mahmoud Mostafa, Anas Abou, El Kalam, Christian FraboulAbstract:Abstract — security and QoS are the two most precious objectives for network systems to be attained. Unfortunately, they are in conflict, while QoS tries to minimize processing delay, strong security protection requires more processing time and cause Packet delay. This article is a step towards resolving this conflict by extending the firewall session table to accelerate NAT, QoS classification, and routing processing time while providing the same level of security protection. Index Terms — Stateful Packet Filtering; firewall; session/state table; QoS; NAT; Routing. 1