Two Level State Machine Architecture for Content Inspection Engines

M Yazdani, Wojciech Frączak, Feliks J. Welfeld, Ioannis Lambadaris · 2006

Abstract — Content inspection technology is promising to address the growing demands of network security and contentaware networking. The component of a network device responsible for content inspection is called Content Inspection Engine (CIE). In content inspection processing, both headers and payload of packets are parsed to determine their content and classify them based on administrative policies. Due to the inclusion of complex payload processing in content inspection, a large amount of processing is required for each data packet, making content inspection a primary bottleneck in high performance routers that support gigabit link capacities. Therefore, there is a need for solutions that can inspect packets quickly with reasonable amount of storage requirements. We describe an architecture based on high performance state machines which provides an efficient solution to this problem by processing multiple characters per state transition. In this architecture the CIE is implemented on a Two-Level State Machine (TLSM). The TLSM implementation exploits the dependencies of policy rules to compress the policy and reduce memory requirements. Using TCAM units in the TLSM for performing fast multiple-character matching operations, makes a wire-speed content inspection possible. We also propose to use a new criterion called worstcase throughput as an appropriate metric for speed evaluation of CIEs. It is shown that this criterion can be efficiently calculated by applying existing algorithms for the Minimum Weight to Time Ratio problem, to a graph-based model of the functionality of CIEs. I.

Read the paper · More papers on PaperTik