Rechercher des projets européens

Deep Packet Inspection to Next Generation Network Devices (DPI)
Date du début: 1 nov. 2010, Date de fin: 31 oct. 2016 PROJET  TERMINÉ 

"Deep packet inspection (DPI) lies at the core of contemporary Network Intrusion Detection/Prevention Systems and Web Application Firewall. DPI aims to identify various malware (including spam and viruses), by inspecting both the header and the payload of each packet and comparing it to a known set of patterns. DPI are often performed on the critical path of the packet processing, thus the overall performance of the security tools is dominated by the speed of DPI.Traditionally, DPI considered only exact string patterns. However, in modern network devices patterns are often represented by regular expressions due to their superior expressiveness. Matching both exact string and regular expressions are well-studied area in Computer Science; however all well-known solutions are not sufficient for current network demands: First, current solutions do not scale in terms of speed, memory and power requirements. While current network devices work at 10-100 Gbps and have thousands of patterns, traditional solutions suffer from exponential memory size or exponential time and induce prohibitive power consumption. Second, non clear-text traffic, such as compressed traffic, becomes a dominant portion of the Internet and is clearly harder to inspect.In this research we design new algorithms and schemes that cope with today demand. This is evolving area both in the Academia and Industry, where currently there is no adequate solution.We intend to use recent advances in hardware to cope with these demanding requirements. More specifically, we plan to use Ternary Content-Addressable Memories (TCAMs), which become standard commodity in contemporary network devices. TCAMs can compare a key against all rules in a memory in parallel and thus provide high throughput. We believ"

Details

1 Participants partenaires