Gregorius Aldo Radityatama, Charles Lim, Heru Purnomo Ipung
{"title":"面向nDPI的全面企业软件支持","authors":"Gregorius Aldo Radityatama, Charles Lim, Heru Purnomo Ipung","doi":"10.1109/ICOICT.2018.8528792","DOIUrl":null,"url":null,"abstract":"Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.","PeriodicalId":266335,"journal":{"name":"2018 6th International Conference on Information and Communication Technology (ICoICT)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2018-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Toward Full Enterprise Software Support on nDPI\",\"authors\":\"Gregorius Aldo Radityatama, Charles Lim, Heru Purnomo Ipung\",\"doi\":\"10.1109/ICOICT.2018.8528792\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.\",\"PeriodicalId\":266335,\"journal\":{\"name\":\"2018 6th International Conference on Information and Communication Technology (ICoICT)\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-05-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 6th International Conference on Information and Communication Technology (ICoICT)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ICOICT.2018.8528792\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 6th International Conference on Information and Communication Technology (ICoICT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOICT.2018.8528792","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Next Generation Firewall (NGFW) adds new capabilities of a standard firewall with an ability to inspect packets' contents, thus increasing precision. Three main usages of NGFW are to improve the Quality of Service (QoS) of a business, as an application-based filtering firewall, and to protect the network from known security threats. A complete NGFW system has three main components: Deep Packet Inspection (DPI), Intrusion Prevention System (IPS), and an extra-firewall intelligence mechanism. One example of open-source DPI implementations is called nDPI. As the number of enterprise applications (used in the commercial organizations) continues to rise, nDPI is also lagging in terms of coverage for enterprise software support. The aim of this research is to design and implement better enterprise-grade software support protocols on nDPI. Five common enterprise applications were chosen and implemented. The experiment results were then compared with the commercial implementation of NGFW in terms of overall precision and performance of nDPI. The results show that the accuracy of nDPI the new protocols implemented reaches more than 90% with a small (less than 3,5%) increase of CPU execution time and very small (less than 1%) increase of peak heap memory usage.