LASF: A flow scheduling policy in stateful packet inspection systems

Zhang Zhibin*, Zhang Yanjun, Guo Li, Fang Binxing

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

3 Citations (Scopus)

Abstract

Current increase in network bandwidth raised an aggressive challenge in network security, and stateful packet inspection based security systems is playing a more and more important role. Recent advances in scheduling theory show that it is possible to reduce the expected mean response time of a queuing system, simply by changing the order in which we schedule the requests according to the job size, which is so called size-based scheduling policy. In this paper, we start by an analysis of connection sojourn time distribution of network traffic. Based on this analysis, first we design a two level session table in order to avoid session table explosion. Then we propose a connection scheduling policy in stateful packet inspection systems called LASF (Least Attained Sojourn First). We show that our policy can improve mean response time and flow throughput especially when system is overloaded. Finally we assess the costs of LASF in terms of unfairness.

Original languageEnglish
Title of host publication12th IEEE International Symposium on Computers and Communications, ISCC '07
Pages87-93
Number of pages7
DOIs
Publication statusPublished - 2007
Externally publishedYes
Event12th IEEE International Symposium on Computers and Communications, ISCC '07 - Aveiro, Portugal
Duration: 1 Jul 20074 Jul 2007

Publication series

NameProceedings - IEEE Symposium on Computers and Communications
ISSN (Print)1530-1346

Conference

Conference12th IEEE International Symposium on Computers and Communications, ISCC '07
Country/TerritoryPortugal
CityAveiro
Period1/07/074/07/07

Fingerprint

Dive into the research topics of 'LASF: A flow scheduling policy in stateful packet inspection systems'. Together they form a unique fingerprint.

Cite this