ANALYSIS OF LINUX OS SECURITY TOOLS FOR PACKET FILTERING AND PROCESSING

D. Melkov, S. Paulikas
{"title":"ANALYSIS OF LINUX OS SECURITY TOOLS FOR PACKET FILTERING AND PROCESSING","authors":"D. Melkov, S. Paulikas","doi":"10.3846/mla.2021.15180","DOIUrl":null,"url":null,"abstract":"Open-source software and its components are widely used in various products, solutions, and applications, even in closed-source. Majority of them are made on Linux or Unix based systems. Netfilter framework is one of the examples. It is used for packet filtering, load-balancing, and many other manipulations with network traffic. Netfilter based packet filter iptables has been most common firewall tool for Linux systems for more than two decades. Successor of iptables – nftables was introduced in 2014. It was designed to overcome various iptables limitations. However, it hasn’t received wide popularity and transition is still ongoing. In recent years researchers and developers around the world are searching for solution to increase performance of packet processing tools. For that purpose, many of them trying to utilize eBPF (Extended Berkeley Packet Filter) with XDP (Express Data Path) data path. This paper focused on analyzing Linux OS packet filters and comparing their performances in different scenarios.","PeriodicalId":30324,"journal":{"name":"Mokslas Lietuvos Ateitis","volume":"4 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2021-08-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Mokslas Lietuvos Ateitis","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.3846/mla.2021.15180","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Open-source software and its components are widely used in various products, solutions, and applications, even in closed-source. Majority of them are made on Linux or Unix based systems. Netfilter framework is one of the examples. It is used for packet filtering, load-balancing, and many other manipulations with network traffic. Netfilter based packet filter iptables has been most common firewall tool for Linux systems for more than two decades. Successor of iptables – nftables was introduced in 2014. It was designed to overcome various iptables limitations. However, it hasn’t received wide popularity and transition is still ongoing. In recent years researchers and developers around the world are searching for solution to increase performance of packet processing tools. For that purpose, many of them trying to utilize eBPF (Extended Berkeley Packet Filter) with XDP (Express Data Path) data path. This paper focused on analyzing Linux OS packet filters and comparing their performances in different scenarios.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
分析Linux操作系统安全工具的包过滤和处理
开源软件及其组件广泛应用于各种产品、解决方案和应用程序中,甚至在闭源中也是如此。它们中的大多数是在基于Linux或Unix的系统上制作的。Netfilter框架就是其中一个例子。它用于包过滤、负载平衡和许多其他网络流量操作。二十多年来,基于Netfilter的包过滤器iptables一直是Linux系统中最常见的防火墙工具。iptables的后继产品——nftables于2014年推出。它被设计用来克服各种iptables的限制。然而,它并没有得到广泛的普及,转型仍在进行中。近年来,世界各地的研究人员和开发人员都在寻找提高数据包处理工具性能的解决方案。为此,他们中的许多人试图利用eBPF(扩展伯克利包过滤器)与XDP(快速数据路径)数据路径。本文重点分析了Linux操作系统包过滤器,并比较了它们在不同场景下的性能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
42
期刊最新文献
ARTIFICIAL NEURAL NETWORKS WITH DYNAMIC SYNAPSES: A REVIEW NOISE BARRIERS EFFICIENCY DEPENDENCE ON THEIR SHAPE AND GEOMETRY RESEARCH ON THE PHYSICAL AND CHEMICAL PROPERTIES OF SEWAGE TREATMENT SLUDGE BIOCHAR AND ITS PREPARATION FOR WASTEWATER RESEARCH OF METHODS FOR IMPROVING ENERGY EFFICIENCY AND EMISSIONS REDUCTION IN DISTRIBUTION STATION OF NATURAL GAS TRANSMISSION NETWORK THE EVALUATION OF ROAD INFRASTRUCTURE FOR SELF-DRIVING VEHICLES
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1