Skip to main navigation Skip to search Skip to main content

Session table architecture for defending SYN flood attack

  • Xin Li*
  • , Zhenzhou Ji
  • , Mingzeng Hu
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Stateful Inspection has become a classical technology for network firewall. Existing session table architectures of Stateful Inspection firewalls cause high time cost of timeout processing. A new architecture is proposed. The new architecture divides a session entry into two separate parts, and designs different data structures for each other. On the base of multi-queue architecture, dynamical timeouts according to available resource improve securities of protected hosts against SYN flood attack. Experimental results show that the new architecture can work well in Gigabit Ethernet network.

Original languageEnglish
Title of host publicationInformation and Communications Security - 7th International Conference, ICICS 2005, Proceedings
PublisherSpringer Verlag
Pages220-230
Number of pages11
ISBN (Print)3540309349, 9783540309345
DOIs
StatePublished - 2005
Externally publishedYes
Event7th International Conference on Information and Communications Security, ICICS 2005 - Beijing, China
Duration: 10 Dec 200513 Dec 2005

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3783 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference7th International Conference on Information and Communications Security, ICICS 2005
Country/TerritoryChina
CityBeijing
Period10/12/0513/12/05

Fingerprint

Dive into the research topics of 'Session table architecture for defending SYN flood attack'. Together they form a unique fingerprint.

Cite this