摘要
网络带宽的增长和频繁的网络攻击给状态封包检测等网络安全系统的性能带来了很大挑战。通过分析TCP连接建立延迟时间分布特性和连接逗留时间分布特性,设计了一个两级连接状态表,很好地解决了检测系统中的连接状态表急剧增长问题。然后,基于经典排队论和高速骨干网的TCP连接特性提出了一个流调度策略LASF(Least Attained Sojourn First)。通过实验证明,该策略能够在系统负载过重时显著提高系统的连接吞吐率等性能。
Current increase in network bandwidth and frequently network attack raise an aggressive challenge in network security systems based stateful packet inspection.In this paper;we start by an analysis of TCP connection setup time and sojourn time distribution of network traffic.Based on this analysis,we design a two level session table in order to avoid session table explosion. Then we propose a connection scheduling policy in stateful packet inspection systems called LASF(Least Attained Sojourn First), which based on classical queuing theory and TCP connection characteristic in high speed network.It shows that this policy can improve flow throughput especially when system is overloaded.
出处
《计算机工程与应用》
CSCD
北大核心
2007年第28期111-114,176,共5页
Computer Engineering and Applications
基金
国家高技术研究发展计划(863)(the National High-Tech Research and Development Plan of China under Grant No.2005AA142110
No.2006AA01Z452)。
关键词
状态封包检测
调度
连接状态表
逗留时间最小优先
stateful packet inspection
scheduling
session table
Least Attained Sojourn First(LASF)