首页> 外文会议> >Adding Value to TCP/IP Based Information exchange Security by Specialized Hardware
【24h】

Adding Value to TCP/IP Based Information exchange Security by Specialized Hardware

机译:通过专用硬件为基于TCP / IP的信息交换安全性增值

获取原文

摘要

Complexity of the attack space existent within the scope TCP/IP based communications makes the security problem extremely wide. Most of the transmitted data has to be processed on a daily basis by firewalls, IDSes and/or other security enforcing technologies. It is possible, however, to divide the complex security threat space and provide fast and efficient solutions to deal with some subspaces. This would reallocate the processing into specialised devices and would take some processing burden off the stated conventional technologies. A specialised hardware architecture capable of sustaining high throughput rates of up to 40 Gbps when implemented in an FPGA platform will serve as one such example. In its current development phase the hardware solution presented processes and verifies the TCP/IP specific reassembly mechanism. The misuse of the reassembly mechanism has historically led to different types of security breaches while new instances can arise unexpectedly. The presented work can be seen as a systemic solution for the monitoring of the misuse of the reassembly mechanism for preventive perspective.
机译:在基于TCP / IP的通信范围内,攻击空间的复杂性使安全问题变得极为广泛。大多数传输的数据必须每天通过防火墙,IDS和/或其他安全实施技术进行处理。但是,可以划分复杂的安全威胁空间,并提供快速有效的解决方案来处理某些子空间。这将把处理重新分配到专用设备中,并将减轻所述传统技术的处理负担。当在FPGA平台中实现时,一种能够维持高达40 Gbps的高吞吐速率的专用硬件架构将是一个这样的例子。在其当前的开发阶段,提出的硬件解决方案处理并验证了TCP / IP特定的重组机制。过去,滥用重组机制已导致不同类型的安全漏洞,而新实例可能会意外出现。所提出的工作可以看作是系统的解决方案,用于从预防的角度监视重组机制的滥用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号