Publication | Closed Access
A multi-gigabit rate deep packet inspection algorithm using TCAM
39
Citations
9
References
2005
Year
Hardware SecurityNetwork FlowsTcam LookupsEngineeringInternet Traffic AnalysisIntrusion Detection SystemDenial-of-service AttackComputer EngineeringComputer ArchitectureNetwork Traffic MeasurementHigh-speed NetworkingComputer ScienceNetwork ProtectionTcam SizeSignal Processing
With the increasing importance of network protection from cyber threats, it is requested to develop a multi-gigabit rate pattern-matching method for protecting against malicious attacks in high-speed network. This paper devises a high-speed deep packet inspection algorithm with TCAM by using an m-byte jumping window pattern-matching scheme. The proposed algorithm significantly reduces the number of TCAM lookups per payload by m times with the marginally enlarged TCAM size which can be implemented by cascading multiple TCAMs. Due to the reduced number of TCAM lookups, we can easily achieve multi-gigabit rate for scanning the packet payload. It is shown by simulation that for the Snort rule with 2,247 patterns, our proposed algorithm supports more than 10 Gbps rate with a 9 Mbit TCAM.
| Year | Citations | |
|---|---|---|
Page 1
Page 1