A Parallel Packet Screen for High Speed Networks

  • Authors:
  • Carsten Benecke

  • Affiliations:
  • -

  • Venue:
  • ACSAC '99 Proceedings of the 15th Annual Computer Security Applications Conference
  • Year:
  • 1999

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper demonstrates why security issues related to the continually increasing bandwidth of High Speed Networks (HSN) cannot be addressed with conventional firewall mechanisms. A single packet screen running on a fast computer is not capable of filtering all packets traversing a Fast/Gigabit Ethernet. This problem can be addressed by using parallel processing methods to implement a fast, scalable packet screen for Ethernets. The paper shows how hardware may be utilized to distribute the network load among such parallel packet screens. Empirical results using `off-the-shelf' equipment indicate that this approach is usable.