A Distributed Cooperative Mechanism Of Software Based Network Security Filtering

Qin Xin,Jianping Wu,Ke Xu,Shu Yang,Jisheng Pei
2015-01-01
Abstract:Routers must perform packet filtering at high speeds to implement critical functions in todays networked computing systems, i.e., firewalls. With serious security situations, and more and more kinds of validation and filter-ing rules emerging, the routers and firewalls now undertake more burden than ever. In routers for large networks, the filtering table, e.g., access control list, gets larger and larger, which easily exceed the limited capacity and brings high power consumption and financial cost. Therefore we are motivated to seek a kind of effective mechanism to solve these problems, which needs to be very easy for deployment, and has strong and proven ability for security filtering. We propose a distributed and cooperative mechanism of software filtering based on finite state machine in which the filtering tasks are split and shared by all the routers rather than relying only on the ingress routers for computation.
What problem does this paper attempt to address?