首页> 外文会议>WSEAS International Conferences >FPGA-based hardware implementation for network intrusion detection system rule matching module
【24h】

FPGA-based hardware implementation for network intrusion detection system rule matching module

机译:基于FPGA的网络入侵检测系统规则匹配模块的硬件实现

获取原文

摘要

The objective of this research is to design and develop a fast string matcher using the content addressable memory technology. It is appropriate for use in applications that require a variable width dynamic string matcher, where the content of the matching module has to be varied within a certain time period. This alteration includes the need to add, remove or even modify the content without the need to change the module, it is capable of matching thousands of complex patterns at gigabit network rates for network intrusion Detection systems (NIDS). The content of the string matcher is padded with don't cares in order to solve the length difference problem between words. The products of this work include a software program that translate and compress standard intrusion detection patterns into binary Strings to be stored into the Matcher CAM. A typical feature for this matcher is that the length of each word is independent from the others. Changing the contents of this string matcher is a simple memory rewrite task no needs for reconfiguration the FPGA circuits. This module can be used in applications that require packet-level fire-wall based security systems. Moreover, we present a detailed comparison with different hardware implemented NIDS algorithms.
机译:本研究的目的是使用内容可寻址存储器技术来设计和开发快速串匹配器。它适用于需要可变宽度动态串匹配器的应用程序,其中匹配模块的内容必须在特定时间段内变化。此更改包括添加,删除甚至修改内容的需要,而无需更改模块,它能够匹配千兆位网络速率的数千个复杂模式,用于网络入侵检测系统(NID)。字符串匹配器的内容用不关心填充,以便解决单词之间的长度差异问题。该工作的产品包括一个软件程序,它将标准入侵检测模式转换为二进制字符串以存储到匹配凸轮中。此匹配器的典型特征是每个单词的长度与其他单词无关。更改此字符串匹配器的内容是一个简单的内存重写任务,无需重新配置FPGA电路。该模块可用于需要基于数据包级灭火墙的安全系统的应用程序。此外,我们向实现的NIDS算法提供了详细的不同硬件的比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号