Abstract Packet classification is a cornerstone of network security functions, such as firewalls, access control, and network metering. It involves taking different actions on packets based on security rules to implement these network security functions. As networks continue to evolve and the number of network instances rapidly increases, the complexity and size of network security rule sets are also expanding. Additionally, autonomous defense systems with artificial intelligence that can detect and block online attacks have become a new trend in network security. Packet classifiers need to not only achieve fast rule matching under large rule sets but also support rapid rule updates in order to deploy security rules issued by online defense systems in a timely manner. However, existing packet classification methods struggle to balance lookup speed with update performance. To achieve rapid rule matching and support fast rule updates in networks, we propose a novel approach called the Learned Index Updatable Tree (LIPT) to address this challenge. LIPT partitions the rule set into single-field non-overlapping subsets and constructs dynamic learned index trees for eac
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً