Fast and Complete Conflict Detection for Packet Classifiers

Chin-Yu Lai, Pi‐Chung Wang · IEEE Systems Journal · 2014

Packet classification filters are used to classify packets based on header fields. A filter conflict occurs when two or more filters overlap, causing an ambiguity in packet classification. These conflicts may cause quality-of-service failures, security vulnerabilities, or routing errors in network services, e.g., differentiated services and firewalls. There are two types of conflicts, i.e., overlapping and subset. While the subset conflict problem can be solved by reordering filters, overlapping conflicts are resolved by inserting resolve filters. None of the existing algorithms detects both types of conflicts for multidimensional filters with arbitrary-range fields. To fill the research gap, we present a series of algorithms based on a previous algorithm that reports all overlapping filters without identifying overlapping conflicts. We improve the previous algorithm to extract overlapping conflicts by modifying either data structures or operations. To further reduce the cost of conflict detection, we define new data structures to process range fields with their boundary addresses. The algorithm based on new bit vectors can detect partial overlaps between multidimensional filters with arbitrary ranges. Our experimental results show that the new algorithm is two times faster than the algorithms based on the original data structures in detecting both types of conflicts.

Read the paper · More papers on PaperTik