首页> 外文会议>IEEE/IFIP International Symposium on Rapid System Prototyping >Flexible Software-Hardware Network Intrusion Detection System
【24h】

Flexible Software-Hardware Network Intrusion Detection System

机译:灵活的软件 - 硬件网络入侵检测系统

获取原文

摘要

Network Intrusion Detection System (NIDS) demands have been steadily increasing over the past few years. Current solutions using software become inefficient running on high speed high volume networks and will end up dropping packets. Hardware solutions are available and result in much higher efficiency but present problems such as flexibility and cost. Our proposed system uses a modified version of Snort, a robust widely deployed open-sourced NIDS. Snort spends a significant fraction of its processing time doing pattern matching. Our proposed system runs Snort in software until it gets to the pattern matching function and then offloads that processing to the Field Programmable Gate Array (FPGA). The hardware is able to process data at up to 1.7GB/s on one Xilinx XC2VP100 FPGA. Our system is more flexible than other FPGA string matching designs in that the rules are not hard-coded. The design is scalable and allows FPGAs to be used in parallel to increase the processing speed even further.
机译:在过去几年中,网络入侵检测系统(NIDS)需求稳步增加。使用软件的当前解决方案在高速大量网络上运行效率低下,并将最终丢弃数据包。有用硬件解决方案可用,导致更高的效率,但存在灵活性和成本等问题。我们建议的系统使用Snort的修改版本,一个强大的广泛部署的开源NID。 Snort花了一小部分的处理时间做模式匹配。我们所提出的系统在软件中运行Snort,直到它到达模式匹配功能,然后卸载到现场可编程门阵列(FPGA)的处理。硬件能够在一个Xilinx XC2VP100 FPGA上处理高达1.7GB / s的数据。我们的系统比其他FPGA字符串匹配设计更灵活,因为规则不是硬编码的。设计是可扩展的,并且允许平行使用FPGA以进一步增加处理速度。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号