Vol.
17
NO.3
loumal
0/
Southwest liaotong University (English Edition)
Ju
l. 2009
Ar
ticle
ID:
1005-2429(2009)03
-0
185-07
A Real-Time
TCP
Stream
Reassembly
Mechanism
in
High-Speed Network
XIONG
Bing
(熊兵),
CHEN
Xiao-su
(陈晓苏)
"
CHEN
Ning
(陈宁)
School
0/
Co
叩脚
r
Science and
TechTWlogy
, Huazhong University
0/
Science and Technology , Wuhan 430074 , China
Abstract
Wi
由
the
continual
growth
of
the
variety
and
complexity
of
network
crime
means
,
th
巳
tradi
ti
onal
pac~
巳
t
feature
matching
cannot
detect
a1
1
kinds
of intrusion behaviors completely.
It
is
urgent
to
reassemble
network
stream
to
p巳
do
口
n
packet processing
at
a
semantic
1
巳
vel
above
the
network
layer.
This
paper
presents
an
efficient
TCP
stre
缸
n
reassembly
mechanism
for
real-tirne
processing
of
high-speed
network
traffic.
By
an
a1
yzing
也巳
characteristics
of
network
stream
in
high-speed
network
and
TCP
connection
establishment
process
,
sever
a1
polices
for
designing
由
e
reassembly
mechanism
are
buil
t.
τben
,也
e
reassembly irnplementation
is
elaborated
in
accordance
with
由
e
policies.
Finally
,也
e
reassembly
mechanism
is
compared
with
由
e
traditional
reassembly
mechanism
by
the
network
traffic captured
in
a
typical
gigabit
gateway.
Experiment
results illustrate
that
the
reassembly
mechanism
is
efficient
and
can
satisfy
出
e
real-time
prope
呵
r
requirement of
traffic
analysis
system
in
high-speed
network
Key words
TCP
stream
reassembly; High-speed network;
Re
a1
-time
prope
口
y;
Reassembly
policy
Introduction
Th
e traditional method
di
旺
erentiates
between
benign traffic and malicious traffic cmefly
by
scanning
the
incoming IP packets in terms
of
sensitive informa-
tion matcmng. However
, with network
crim
巳
means
becoming more complex and various , the traditional
method cannot find out some special intrusion behav-
iors. A good example is that
,
if
sensitive information
is fragmented into several different
IP
packets inten-
Received
Feb.
24
, 2008;
r
巳
vision
accepted
D
巳
c.
11
,
2008
Foundation itcm
National
Hi
gh-Tech
R
巳
search
and
Develop-
ment
Program
of
China
(863 Program) (No.
2007
AA01
Z3
09)
Biographies
XIONG
Bing
(1981
一),
P
hD
candidate.
His
research interest
is
in
network
and
information
security.
CHEN
Xiao-su
(1953
-),
professo
r.
His research interest
is
in
net-
work
and
information
security.
CHEN
Ning
(1980-)
, P
hD
candidat
巳.
His
research
interest
is
in
network
and
information
security.
味
Corresponding
autho
r.
Te
l. :
027
-8
7541689; E-mail: x s
chen@mai
l.
hus
t.
edu.
cn
tionally , the packet feature will
be
lost and the mali-
cious behavior cannot be detected.
To
improve the
accuracy
of
malicious traffic detection , the system can
no
longer only use packet-level processing
but
must in-
stead reassemble all packets
of
every
TCP
stre
但丑
into
a
whole session to perform application-level analysis.
To
the best
of
the
author's
knowledge , there was
only a little special research regarding
TCP
'stream
reassembly
in
high-speed network. In a project close-
ly related to
our
work
,
Dharmapurikar
and
Paxson[lJ
presented a
design
of
a hardware-based high-speed
TCP
reassembly mechanism that
was
robust against
attacks. His
work
was creative and comprehensive in
the robustness
of
reassembly-Hariaoka
et
al.[2I pro-
posed an efficient
TCP
reassembly mechanism for lay-
er
7-aware
network
intrusion detectionlprevention
systems. His
work
focused
on
the
packet
processing
approach before
going
to
TCP
reassembler
but
not
由巳
reassembly procedure.
Necker
et
al.
[3J
, using Xilinx
Virtex technology
, devised a high performance
TCP
stream reassembly and state tracking module targeted