位置:成果数据库 > 期刊 > 期刊详情页
基于动态IP黑名单的入侵防御系统模型
  • 期刊名称:卢先锋, 杨频, 梁刚, 基于动态IP黑名单的入侵防御系统模型. 计算机工程与设计, 32(1):
  • 时间:0
  • 分类:TP311[自动化与计算机技术—计算机软件与理论;自动化与计算机技术—计算机科学与技术]
  • 作者机构:[1]四川大学计算机学院,四川成都610065
  • 相关基金:基金号(60873246)国家自然科学基金信息科学部
  • 相关项目:网络安全态势实时定量感知模型
中文摘要:

针对如何利用高性能多核化设备,提高网络安全产品的处理能力,设计和实现了一种基于x86架构的Llinux平台多核绑定技术。该技术首先建立DMA缓冲队列映射,减少网卡访问次数,采用SIMD多核思想设计和实现了虚拟数据桶,并对进入数据桶的数据实施负载均衡;将Netfilter主函数多线程化,并采用内核线程绑定技术将多线程绑定到指定核.实验结果表明,DMA缓冲队列映射可以提高网络设备的I/O吞吐量,虚拟数据桶减少了数据包二次拷贝的开销,节省内核态内存,多核绑定技术提高网络安全设备多核利用率和数据包处理能力。

英文摘要:

Focusing on how to use high-performance multi-core technology equipment,a novel architecture based-on X86 binding technique is introduced to exploit the performance benefit of such multi-core device to improve the processing capacity of network security product.DMA caching array mapping is built to reduce the network card access.Virtual data bucket is designed and implemented involving SIMD design pattern,and load balancing is applied for optimization of data bucket.Netfilter is discussed in detail and multi-threading main function is introduced.Using kernel thread binding,threads can be specified to designated core in the device.Experiments have been done to illustrate an improved result.DMA caching array mapping increases the I/O throughout capacity;adopting of virtual data bucket reduces the cost of duplicated copy of data and then saves the kernel memory usage;multi-core binding technique can increase the operation rate of multi-cores of network security device hence improves the processing capacity of data packet.

同期刊论文项目
期刊论文 61 会议论文 11
同项目期刊论文