首页> 外文会议>Proceedings of the 2005 ACM symposium on Architecture for networking and communications systems >High-throughput linked-pattern matching for intrusion detection systems
【24h】

High-throughput linked-pattern matching for intrusion detection systems

机译:入侵检测系统的高通量链接模式匹配

获取原文
获取原文并翻译 | 示例

摘要

This paper presents a hardware architecture for highly efficient intrusion detection systems. In addition, a software tool for automatically generating the hardware is presented.Intrusion detection for network security is a compute-intensive application demanding high system performance. By moving both the string matching and the linking of multi-part rules to hardware, our architecture leaves the host system free for higher-level analysis. The tool automates the creation of efficient Field Programmable Gate Array architectures (FPGA). The generated hardware allows an FPGA-based system to perform deep-packet inspection of streams at up to 10 Gb/s line rates at a high level of area efficiency. Going beyond previous basic string-matching implementations that offer only single-string matching, the architecture provides support for rules requiring complex, linked (correlated-content) constructions. This allows most Snort content-linking extensions including `distance' and `within' bounding restrictions.
机译:本文提出了一种用于高效入侵检测系统的硬件体系结构。此外,还提供了一种用于自动生成硬件的软件工具。用于网络安全的入侵检测是一种计算量大的应用程序,需要较高的系统性能。通过将字符串匹配和多部分规则的链接移动到硬件,我们的体系结构使主机系统可以自由进行更高级别的分析。该工具可自动创建高效的现场可编程门阵列架构(FPGA)。生成的硬件允许基于FPGA的系统以最高的区域效率以高达10 Gb / s的线速执行流的深包检查。除了以前的仅提供单字符串匹配的基本字符串匹配实现之外,该体系结构还支持需要复杂的链接(相关内容)构造的规则。这允许大多数Snort内容链接扩展,包括“距离”和“范围内”限制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号