1,721,167 research outputs found
Enabling precise traffic filtering based on protocol encapsulation rules
Current packet filters have a limited support for expressions based on protocol encapsulation relationships and some constraints are not supported at all, such as the value of the IP source address in the inner header of an IP-in-IP packet. This limitation may be critical for a wide range of packet filtering applications, as the number of possible encapsulations is steadily increasing and network operators cannot define exactly which packets they are interested in. This paper proposes a new formalism, called eXtended Finite State Automata with Predicates (xpFSA), that provides an efficient implementation of filtering expressions, supporting both constraints on protocol encapsulations and the composition of multiple filtering expressions. Furthermore, it defines a novel algorithm that can be used to automatically detect tunneled packets. Our algorithms are validated through a large set of tests assessing both the performance of the filtering generation process and the efficiency of the actual packet filtering code when dealing with real network packets
Procedimento di ispezione di pacchetti di dati, relativo dispositivo e prodotto informatico
On the Efficiency of PGPS-based Packet and Cell Switching Technologies for Traffic with Guaranteed Delay
Method for data packet inspection, related device and computer/program product
Described herein is a data-packet-inspection device. The device (20a) comprises a first communication interface (202), which can be connected to a first network, and a second communication interface (206), which can be connected to a second network (30). The device (20a), receives, through the first communication interface (202), one or more data packets that may comprise a request of a first host (10) connected to the first network for access to a resource managed by a second host (40) connected to the second network. The device (20a) detects the access request and analyses the access request for detecting the respective resource requested. Next, the device (20a) determines whether the resource requested is blocked or allowed and identifies the status of the response to the aforesaid access request as blocked or allowed. The device (20a) in the meantime sends the access request to the second communication interface. Consequently, the device (20a) can receive, through the second communication interface (206), one or more data packets that may comprise a response of the second host (40) to the access request. The device (20a) detects this response and verifies the status of the response to determine whether the response is blocked or allowed. For example, in the case where the response is blocked, the device (20a) inhibits forwarding of at least part of the response
Is the computing continuum already here?
The computing continuum, a novel paradigm that extends beyond the current silos of cloud and edge computing, can enable the seamless and dynamic deployment of applications across diverse infrastructures. By utilizing the cloud-native features and scalability of Kubernetes, this concept promotes deployment transparency, communication transparency, and resource availability transparency. Key features of this paradigm include intent-driven policies, a decentralized architecture, multi-ownership, and a fluid topology. Integral to the computing continuum are the building blocks of dynamic discovery and peering, hierarchical resource continuum, resource and service reflection, network continuum, and storage and data continuum. The implementation of these principles allows organizations to foster an efficient, dynamic, and seamless computing environment, thereby facilitating the deployment of complex distributed applications across varying infrastructures
Implementation and Characterization of an Advanced Scheduler
Decoupled-CBQ, a CBQ derived scheduler, has been proved being a substantial improvement over CBQ. D-CBQ main advantages are a new set of rules for distributing excess bandwidth and the ability to guarantee bandwidth and delay in a separate way, whence the name "decoupled". This paper aims at the characterization of D-CBQ by means of an extended set of simulations and a real implementation into the ALTQ framework
- …
