面向nDPI的全面企业软件支持

Gregorius Aldo Radityatama, Charles Lim, Heru Purnomo Ipung
{"title":"面向nDPI的全面企业软件支持","authors":"Gregorius Aldo Radityatama, Charles Lim, Heru Purnomo Ipung","doi":"10.1109/ICOICT.2018.8528792","DOIUrl":null,"url":null,"abstract":"Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.","PeriodicalId":266335,"journal":{"name":"2018 6th International Conference on Information and Communication Technology (ICoICT)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2018-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Toward Full Enterprise Software Support on nDPI\",\"authors\":\"Gregorius Aldo Radityatama, Charles Lim, Heru Purnomo Ipung\",\"doi\":\"10.1109/ICOICT.2018.8528792\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.\",\"PeriodicalId\":266335,\"journal\":{\"name\":\"2018 6th International Conference on Information and Communication Technology (ICoICT)\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-05-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 6th International Conference on Information and Communication Technology (ICoICT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICOICT.2018.8528792\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 6th International Conference on Information and Communication Technology (ICoICT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOICT.2018.8528792","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

NGFW (Next Generation Firewall)在标准防火墙的基础上增加了对报文内容的检测功能,提高了检测精度。NGFW的主要用途是提高业务的服务质量(QoS),作为基于应用的过滤防火墙,保护网络免受已知的安全威胁。一个完整的NGFW系统主要由三个部分组成:DPI (Deep Packet Inspection)、IPS (Intrusion Prevention system)和防火墙外智能机制。开源DPI实现的一个例子是nDPI。随着企业应用程序(在商业组织中使用)的数量不断增加,nDPI在企业软件支持的覆盖方面也落后了。本研究的目的是在nDPI上设计和实现更好的企业级软件支持协议。选择并实现了五个常见的企业应用程序。然后,将实验结果与NGFW的商业实现在nDPI的整体精度和性能方面进行了比较。结果表明,新协议实现的nDPI精度达到90%以上,CPU执行时间增加很小(小于3.5%),峰值堆内存使用增加很小(小于1%)。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Toward Full Enterprise Software Support on nDPI
Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信