An extensible, system-on-programmable-chip, content-aware Internet firewall

被引:0
|
作者
Lockwood, JW [1 ]
Neely, C [1 ]
Zuver, C [1 ]
Moscola, J [1 ]
Dharmapurikar, S [1 ]
Lim, D [1 ]
机构
[1] Washington Univ, Appl Res Lab, St Louis, MO 63130 USA
来源
FIELD-PROGRAMMABLE LOGIC AND APPLICATIONS, PROCEEDINGS | 2003年 / 2778卷
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
An extensible firewall has been implemented that performs packet filtering, content scanning, and per-flow queuing of Internet packets at Gigabit/second rates. The firewall uses layered protocol wrappers to parse the content of Internet data. Packet payloads are scanned for keywords using parallel regular expression matching circuits. Packet headers are compared to rules specified in Ternary Content Addressable Memories (TCAMs). Per-flow queuing is performed to mitigate the effect of Denial of Service attacks. All packet processing operations were implemented with reconfigurable hardware and fit within a single Xilinx Virtex XCV2000E Field Programmable Gate Array (FPGA). The single-chip firewall has been used to filter Internet SPAM and to guard against several types of network intrusion. Additional features were implemented in extensible hardware modules deployed using run-time reconfiguration.
引用
收藏
页码:859 / 868
页数:10
相关论文
共 47 条
  • [1] Dynamically reconfigurable system-on-programmable-chip
    Kalte, H
    Langen, D
    Vonnahme, E
    Brinkmann, A
    Rückert, U
    10TH EUROMICRO WORKSHOP ON PARALLEL, DISTRIBUTED AND NETWORK-BASED PROCESSING, PROCEEDINGS, 2002, : 235 - 242
  • [2] EDA tools bridge the system-on-programmable-chip
    Dipert, B
    EDN, 2002, 47 (16) : 32 - +
  • [3] Accelerating elliptic curve cryptography on system-on-programmable-chip
    Zhou, Jian-Yang
    Jiang, Xiao-Gang
    2007 INTERNATIONAL WORKSHOP ON ANTI-COUNTERFEITING, SECURITY, AND IDENTIFICATION, 2007, : 292 - +
  • [4] System-on-programmable-chip implementation for on-line face recognition
    Kumar, A. Pavan
    Kamakoti, V.
    Das, Sukhendu
    PATTERN RECOGNITION LETTERS, 2007, 28 (03) : 342 - 349
  • [5] Color tracking for multiple robot control using a system-on-programmable-chip
    Yu, Ying-Hao
    Kwok, N. M.
    Ha, Q. P.
    AUTOMATION IN CONSTRUCTION, 2011, 20 (06) : 669 - 676
  • [6] System-on-programmable-chip implementation of diminishing learning based pattern recognition system
    J. Manikandan
    B. Venkataramani
    International Journal of Machine Learning and Cybernetics, 2013, 4 : 347 - 363
  • [7] System-on-programmable-chip implementation of diminishing learning based pattern recognition system
    Manikandan, J.
    Venkataramani, B.
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2013, 4 (04) : 347 - 363
  • [8] Content-aware Internet application traffic measurement and analysis
    Choi, TS
    Kim, CH
    Yoon, SH
    Park, JS
    Lee, BJ
    Kim, HH
    Chung, HS
    Jeong, TS
    NOMS 2004: IEEE/IFIP NETWORK OPERATIONS AND MANAGMENT SYMPOSIUM: MANAGING NEXT GENERATION CONVERGENCE NETWORKS AND SERVICES, 2004, : 511 - 524
  • [9] iSlideshow: a Content-Aware Slideshow System
    Chen, Jiajian
    Xiao, Jun
    Gao, Yuli
    IUI 2010, 2010, : 293 - 296
  • [10] Neural Adaptive Content-aware Internet Video Delivery
    Yeo, Hyunho
    Jung, Youngmok
    Kim, Jaehong
    Shin, Jinwoo
    Han, Dongsu
    PROCEEDINGS OF THE 13TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, 2018, : 645 - 661