A matching algorithm of Netfilter connection tracking based on IP flow
Ke Zhang, Juan Wang, Dasen Ren · 2008
In order to improve the performance of Netfilter firewall framework of Linux while packets are being matched under the stateful inspection, the thesis, which is based on the analysis of the mechanism of stateful inspection firewall and the data structure of Netfilter connection tracking hash table, puts forward a matching algorithm of connection tracking based on IP flow. The algorithm, through revising the data structure of head node of hash table, adds a pointer pointing to the node of collision list matched successfully last time, to reduce the time which the later packets of related connection uses to traverse collision list. The simulating experiment indicates that the algorithm is able to improve the efficiency of Netfilter firewall stateful inspection.