
PPP: Towards Parallel Protocol Parsing

PPP: Towards Parallel Protocol Parsing
摘要 Network traffic classification plays an important role and benefits many practical network issues,such as Next-Generation Firewalls(NGFW),Quality of Service(QoS),etc.To face the challenges brought by modern high speed networks,many inspiring solutions have been proposed to enhance traffic classification.However,taking many factual network conditions into consideration,e.g.,diversity of network environment,traffic classification methods based on Deep Inspection(DI) technique still occupy the top spot in actual usage.In this paper,we propose a novel classification system employing Deep Inspection technique,aiming to achieve Parallel Protocol Parsing(PPP).We start with an analytical study of the existing popular DI methods,namely,regular expression based methods and protocol parsing based methods.Motivated by their relative merits,we extend traditional protocol parsers to achieve parallel matching,which is the representative merit of regular expression.We build a prototype system,and evaluation results show that significant improvement has been made comparing to existing open-source solutions in terms of both memory usage and throughput. Network traffic classification plays an important role and benefits many practical network issues, such as Next-Generation Firewalls (NGFW), Quality of Service (QoS), etc. To face the challenges brought by modern high speed networks, many inspiring solutions have been proposed to enhance traffic classification. However, taking many factual network conditions into consideration, e.g., diversity of network environment, traffic classification methods based on Deep Inspection (DI) technique still occupy the top spot in actual usage. In this paper, we propose a novel classification system employing Deep Inspection technique, aiming to achieve Parallel Protocol Parsing (PPP). We start with an analytical study of the existing popular DI methods, namely, regular expression based methods and protocol parsing based methods. Motivated by their relative merits, we extend traditional protocol parsers to achieve parallel matching, which is the representative merit of regular expression. We build a prototype system, and evaluation results show that significant improvement has been made comparing to existing open-source solutions in terms of both memory usage and throughput.
作者 SHAO Yiyang
出处 《China Communications》 SCIE CSCD 2014年第10期106-116,共11页 中国通信(英文版)
基金 supported by the National Key Technology R&D Program of China under Grant No.2012BAH46B04
关键词 协议解析 PPP 并行 正则表达式 分类方法 网络流量 服务质量 检测技术 trafficinspection regularparsingclassification deepexpression protocol
  • 相关文献



  • 1Michela Becchi. Regular expression processor, http:// regex.wustl.edu/. 2010.11,15.
  • 2Libnids. http://libnids.sourceforge.net. 2010.11.15.
  • 3Group S. Defcon 9 Capture the Flag Data. http://ictf.cs. ucsb.edu/data/defcon ctf 09. 2010.11,1.
  • 4A1-Fares M, Radhakrishnan S, Raghavan B, et al. Hedera: Dynamic flow scheduling for data center networks. In: Proceedings of the 7th USENIX Conference on Networked Systems Design and Implementation (NSDI). USA: USENIX, 2010.
  • 5McKeown N, Anderson T, Balakrishnan H, et al. OpenFlow: Enabling innovation in campus networks. SIGCOMM Computer Communication Review, 2008, 38(2).
  • 6Sen S, Spatscheck O, Wang D. Accurate, scalable in-network identification of p2p traffic using application signatures. In: Proceedings of the 13th International Conference on World Wide Web. USA: ACM, 2004: 512-520.
  • 7Haffner P, Sen S, Spatscheck O, et al. ACAS: Automated construction of application signatures. In: Proceedings of the 2005 ACM SIGCOMM Workshop on Mining Network Data. USA: ACM, 2005.
  • 8Moore A W, Zuev D. Intemet traffic classification using Bayesian analysis techniques. In: Proceedings of the ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems. Canada: ACM, 2005.
  • 9Callado A, Kelner J, Sadok D, et al. Better network traffic identification through the independent combination of techniques. Journal of Network and Computer Applications, 2010, 33(4): 433-446.
  • 10Bernaille L, Teixeira R, Akodkenou I, et al. Traffic classification on the fly. SIGCOMM Computer Communication Review, 2006, 36(2).








使用帮助 返回顶部