首页> 外文学位 >Hardware-efficient pattern matching algorithms and architectures for fast intrusion detection.
【24h】

Hardware-efficient pattern matching algorithms and architectures for fast intrusion detection.

机译:具有硬件效率的模式匹配算法和体系结构,可实现快速入侵检测。

获取原文
获取原文并翻译 | 示例

摘要

Intrusion detection processors are becoming a predominant feature in the field of network hardware. As demand on more network speed increases and new network protocols emerge, network intrusion detection systems are increasing in importance and are being integrated in network processors. Currently, most intrusion detection systems are software running on a general purpose processor. Unfortunately, it is becoming increasingly difficult for software based intrusion detection systems to keep up with increasing network speeds (OC192 and 10Gbps at backbone networks).;Signature-based intrusion detection systems monitor network traffic for security threats by scanning packet payloads for attack signatures. Intrusion detection systems have to run at wire speed and need to be configurable to protect against emerging attacks. This dissertation describes the concept, structure and algorithms for a special purpose hardware accelerator designed to meet those demands. We consider the problem of string matching which is the most computationally intensive task in intrusion detection. A configurable string matching accelerator is developed with the focus on increasing throughput while maintaining the configurability provided by the software intrusion detection systems. A hardware algorithm for efficient data storage and fast retrieval is used to compress, store and retrieve attack signatures. Our algorithms reduce the size of the rules to fit on chip and enables intrusion detection to run at line rates and faster.
机译:入侵检测处理器正在成为网络硬件领域的主要功能。随着对更高网络速度的需求增加以及出现了新的网络协议,网络入侵检测系统的重要性日益提高,并已集成到网络处理器中。当前,大多数入侵检测系统都是在通用处理器上运行的软件。不幸的是,基于软件的入侵检测系统要跟上不断增长的网络速度(骨干网的OC192和10Gbps)变得越来越困难。基于签名的入侵检测系统通过扫描数据包有效载荷以查看攻击签名来监视网络流量中的安全威胁。入侵检测系统必须以线速运行,并且需要进行配置以防止出现新的攻击。本文描述了为满足这些需求而设计的专用硬件加速器的概念,结构和算法。我们考虑字符串匹配的问题,这是入侵检测中计算量最大的任务。开发了一种可配置的字符串匹配加速器,其重点是在提高吞吐量的同时保持软件入侵检测系统提供的可配置性。用于高效数据存储和快速检索的硬件算法用于压缩,存储和检索攻击特征。我们的算法减小了规则的大小以适合芯片,并允许入侵检测以线速和更快的速度运行。

著录项

  • 作者

    Aldwairi, Monther.;

  • 作者单位

    North Carolina State University.;

  • 授予单位 North Carolina State University.;
  • 学科 Engineering Electronics and Electrical.;Computer Science.
  • 学位 Ph.D.
  • 年度 2006
  • 页码 142 p.
  • 总页数 142
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号