This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
The IEEE Conference on Local Computer Networks 30th Anniversary (LCN'05)l
AntiWorm NPU-based Parallel Bloom Filters for TCP/IP Content Processing in Giga-Ethernet LAN
Sydney, Australia
November 15-November 17
ISBN: 0-7695-2421-4
Zhen Chen, Zhen Chen
Chuang Lin, Chuang Lin
Jia Ni, Jia Ni
Dong-Hua Ruan, Dong-Hua Ruan
Bo Zheng, Bo Zheng
Yi-Xin Jiang, Yi-Xin Jiang

TCP/IP protocol suite carries most application data in Internet. TCP flow retrieval has more security meanings than the IP packet payload. Hence, monitoring the TCP flow has more strength than only monitoring the IP packet payload in the AntiWorm system. The main idea of this paper is to use the flexibility and high performance of Network Processors to scan TCP flow for locating worm?s binary codes, and cut off their propagation. A stateful TCP flow inspection engine is implemented based on IXP Network Processor, which can monitor about 512K flows. The performance issues about IXP Network Processors are evaluated and collected, and an analysis is made for further optimizing the system performance. The system is also demonstrated and proved by using the Internet traces and real assaults of Worms. Software Package TCPScanner 1.0 is also given as a software release of the research.

Index Terms:
Network Security, Worms, Network Processors,TCP/IP Protocol suite, Parallel Bloom Filter, Deep Packet Inspection, Stateful TCP inspection.
Citation:
Zhen Chen, Chuang Lin, Jia Ni, Dong-Hua Ruan, Bo Zheng, Yi-Xin Jiang, "AntiWorm NPU-based Parallel Bloom Filters for TCP/IP Content Processing in Giga-Ethernet LAN," lcn, pp.748-755, The IEEE Conference on Local Computer Networks 30th Anniversary (LCN'05)l, 2005
Usage of this product signifies your acceptance of the Terms of Use.