Title: Resource allocation in network processors for network intrusion prevention systems
Authors: Lin, Yi-Neng
Chang, Yao-Chung
Lin, Ying-Dar
Lai, Yuan-Chen
資訊工程學系
Department of Computer Science
Keywords: network intrusion and detection system;network processor;resource allocation;benchmark;bottleneck
Issue Date: 1-Jul-2007
Abstract: Networking applications with high memory access overhead gradually exploit network processors that feature multiple hardware multithreaded processor cores along with a versatile memory hierarchy. Given rich hardware resources, however, the performance depends on whether those resources are properly allocated. In this work, we develop an NIPS (Network Intrusion Prevention System) edge gateway over the Intel IXP2400 by characterizing/mapping the processing stages onto hardware components. The impact and strategy of resource allocation are also investigated through internal and external benchmarks. Important conclusions include: (1) the system throughput is influenced mostly by the total number of threads, namely I x J, where I and J represent the numbers of processors and threads per processor, respectively, as long as the processors are not fully utilized, (2) given an application, algorithm and hardware specification, an appropriate (1, J) for packet inspection can be derived and (3) the effectiveness of multiple memory banks for tackling the SRAM bottleneck is affected considerably by the algorithms adopted. (C) 2007 Elsevier Inc. All rights reserved.
URI: http://dx.doi.org/10.1016/j.jss.2007.01.032
http://hdl.handle.net/11536/10657
ISSN: 0164-1212
DOI: 10.1016/j.jss.2007.01.032
Journal: JOURNAL OF SYSTEMS AND SOFTWARE
Volume: 80
Issue: 7
Begin Page: 1030
End Page: 1036
Appears in Collections:Articles


Files in This Item:

  1. 000247453800011.pdf

If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.