Skip to main content

A Reconfigurable Approach to Packet Filtering

  • Conference paper
  • First Online:
Field-Programmable Logic and Applications (FPL 2001)

Part of the book series: Lecture Notes in Computer Science ((LNCS,volume 2147))

Included in the following conference series:

Abstract

Network packet classification is an important function for firewalls and filters. Packet classification based on transport-layer headers is widely used, and is specified by providing the filter with a list of rules. The cost of lookup may become a bottleneck in network performance. We present a novel technique for packet classification using FPGAs that exploits the reprogrammable nature of FPGAs. The rules are converted into a boolean expression which is directly implemented as a circuit on an FPGA. This approach is cheaper and simpler than previous hardware implementations, and we have had good experimental results.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 84.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 109.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. S. Ballew. Managing IP Networks with Cisco routers. O’Reilly, 1997.

    Google Scholar 

  2. R.E. Bryant. Symbolic Boolean Manipulation with Ordered Binary-Decision Diagrams. A CM Computing Surveys, 24(3):293–318, September 1992.

    Google Scholar 

  3. P. Gupta and N. McKeown. Packet classification on multiple fields. In Computer Communication Review. ACM SIGCOMM, October 1999.

    Google Scholar 

  4. T. Harbaum, D. Meier, M. Zitterbart, and D. Brökelmann. Flexible hardware support for gigabit routing. In Proc. Kommunikation in Verteilten Systemen (KiVS’99), Darmstadt, Germany, March 1999.

    Google Scholar 

  5. S. Hazelhurst, A. Attar, and R. Sinnappan. Algorithms for improving the dependability of firewall and filter rule lists. In Workshop on the Dependability of IP Applications Platforms and Networks, pages 576–585, New York, June 2000. In Proc. IEEE Int. Conf. Dependable Systems and Networks.

    Google Scholar 

  6. T. Lakshman and D. Stiliadis. High speed policy-based packet forwarding using efficient multi-dimensional range matching. In ACM SIGCOMM’ 98, pages 203–214, Vancouver, August 1998. ACM.

    Google Scholar 

  7. J. McHenry, P. Dowd, T. Carrozzi, F. Pellegrino, and W. Cocks. An FPGA-based coprocessor for ATM firewalls. In Proceedings of the IEEE Symposium on FPGAs for Custom Computing Machines, pages 30–39, April 1997.

    Google Scholar 

  8. David Newman. Firewall on a chip: Fore’s FSA boosts throughput to multigigabit rates. Data Communications, 28(1):44–45, January 1999.

    Google Scholar 

  9. R. Sinnappan. A Reconfigurable Approach to TCP/IP Packet Filtering. MSc Research Report, School of Computer Science, University of the Witwatersrand, 2001.

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2001 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Sinnappan, R., Hazelhurst, S. (2001). A Reconfigurable Approach to Packet Filtering. In: Brebner, G., Woods, R. (eds) Field-Programmable Logic and Applications. FPL 2001. Lecture Notes in Computer Science, vol 2147. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-44687-7_70

Download citation

  • DOI: https://doi.org/10.1007/3-540-44687-7_70

  • Published:

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-42499-4

  • Online ISBN: 978-3-540-44687-3

  • eBook Packages: Springer Book Archive

Publish with us

Policies and ethics