Analysis of hardware implementation of packet classification algorithms
This paper describes network packet classification algorithms for attack detection and prevention systems. Approaches to hardware implementation of network packet classification algorithms using decision trees, field splitting, and parallel processing are presented. The field splitting algorithm in the network context was initially studied in the Field- Split algorithm Bit Vector, the main purpose is to reduce memory consumption. To balance the bandwidth, and delay, which allows to improve the efficiency of power consumption and memory access, DPRAM is proposed for the FSBV algorithm, which will enable data to be read repeatedly. In the packet classification process, the source address, destination address, source port, and destination port are calculated by applying various operations for matching. To operate, to match the fields based on the FSBV algorithm, triggers, LUTs, and various logic elements will be applied.
[1] Madhi D., and Ramasamy K., 2007 , “Network routing algorithms, protocols, and architectures”, Morgan Kaufmann, USA, pp. 1-957.
[2] Gupta P., and McKeown N. b, 1999, “Packet classification using hierarchical intelligent cuttings,” In Proceeding of Hot Interconnects VII, pp. 34-41
[3] Meiners CR, Liu AX, and Torng E., 2010 , “Hardware Based Packet Classification for High Speed Internet Routers”, Springer, New York-USA, pp. 1-122
[4] Taylor, D. E. (2005). Survey and Taxonomy of Packet Classification Techniques. ACM Computing Surveys, 37(3), pp.238-275. DOI: http://dx.doi.org/10.1145/1108956.1108958
[5] Singh, S., Baboescu , F., Varghese, G. and Wang J. (2003). Packet Classification Using Multidimensional Cutting. Proceedings of the 2003 conference on Applications, technologies, architectures, and protocols for computer communications (SIGCOMM '03). pp.213-224. DOI: http://dx.doi.org/10.1145/863955.863980
[6] Baboescu , F., Singh, S. and Varghese, G. (2003). Packet Classification for Core Routers: Is there an alternative to CAMs? IEEE INFOCOM 2003. pp.53-63. DOI: http://dx.doi.org/10.1109/INFCOM.2003.1208658
[7] Srinivasan, V. and Varghese, G. (1998). Faster IP lookups using controlled prefix expansion. ACM SIGMETRICS Performance Evaluation Review. 26(1), pp.1-10. DOI: http://dx.doi.org/10.1145/277858.277863
[8] Hariguchi , Y. (2002). ART – Allotment Routing Table – A Fast Free Multibit Trie Based Routing Table; Webpage: www.hariguchi.org/art
[9] Jiang, W. and Prasanna, V. K. (2009). Field-Split Parallel Architecture for High Performance Multi-Match Packet Classification Using FPGAs. Proceedings of the 21st ACM Symposium on Parallelism in Algorithms and Architectures (SPAA '09). pp.188-196. DOI: http://dx.doi.org/10.1145/1583991.1584044
[10] Yu, F. and Katz, R. H. (2004). Efficient Multi-Match Packet Classification with TCAM. Proceedings 12th IEEE Symposium on Hot Interconnects (HOTI'04). pp.28-34. DOI: http://dx.doi.org/10.1109/CONECT.2004.1375197
[11] Yu, F., Lakshman, TV, Motoyama , MA and Katz, RH 2005. SSA: A Power and Memory Efficient Scheme to Multi-Match Packet Classification. Proceedings of the 2005 ACM Symposium on Architectures for Networking and Communications Systems (ANCS). pp.105-113. DOI: http://dx.doi.org/10.1145/1095890.1095905
[12] Song, H. and Lockwood, J. W. (2005a). Efficient Packet Classification for Network Intrusion Detection using FPGA. FPGA '05: Proceedings of the 2005 ACM/SIGDA 13th international symposium on Field-programmable gate arrays. pp.238-245. DOI: http://dx.doi.org/10.1145/1046192.1046223
[13] Jiang, W. and Prasanna, V. K. (2009). Field-Split Parallel Architecture for High Performance Multi-Match Packet Classification Using FPGAs. Proceedings of the 21st ACM Symposium on Parallelism in Algorithms and Architectures (SPAA '09). pp.188-196. DOI: http://dx.doi.org/10.1145/1583991.1584044
[14] Eatherton , W. (1998). Hardware-based Internet Protocol Prefix Lookups. MS thesis, Electr . Eng. Dept., Washington Univ., St. Louis, MO, USA; http://www.arl.wustl.edu/~jst/studentTheses/wEatherton-1999.pdf
[15] Snort. Snort: Network intrusion prevention and detection system ( ips /ids). http://www.snort.org/
[16] M. Karimov, K. Tashev and M. Yoriqulov , "Problems of increasing efficiency of NIDS by using implementing methods packet classifications on FPGA," 2019 International Conference on Information Science and Communications Technologies (ICISCT), Tashkent, Uzbekistan, 2019 , pp. 1-5, doi: 10.1109/ICISCT47635.2019.9011925.
[17] K. Tashev, I. Durdona and A. Mokhinabonu, "Comparative performance analysis the Aho-Corasick algorithm for developing a network detection system," 2022 International Conference on Information Science and Communications Technologies (ICISCT), Tashkent, Uzbekistan, 2022, pp. 1-7, doi: 10.1109/ICISCT55600.2022.10146815.
[18] K. Tashev and M. Karimov, "New Approach to developing efficient NIDPS," 2021 International Conference on Information Science and Communications Technologies (ICISCT), Tashkent, Uzbekistan, 2021, pp. 1-5, doi: 10.1109/ICISCT52966.2021.9670253.