首页> 外文期刊>Computers, Materials & Continua >High Speed Network Intrusion Detection System (NIDS) Using Low Power Precomputation Based Content Addressable Memory
【24h】

High Speed Network Intrusion Detection System (NIDS) Using Low Power Precomputation Based Content Addressable Memory

机译:使用基于低功耗预计算的内容可寻址存储器的高速网络入侵检测系统(NIDS)

获取原文
获取原文并翻译 | 示例
       

摘要

NIDS (Network Intrusion Detection Systems) plays a vital role in security threats to computers and networks. With the onset of gigabit networks, hardware-based Intrusion Detection System gains popularity because of its high performance when compared to the software-based NIDS. The software-based system limits parallel execution, which in turn confines the performance of a modern network. This paper presents a signature-based lookup technique using reconfigurable hardware. Content Addressable Memory (CAM) is used as a lookup table architecture to improve the speed instead of search algorithms. To minimize the power and to increase the speed, pre-computation based CAM (PBCAM) can be used, as this technique avoids repeated search comparisons. PBCAM employs the two-stage comparison with a parameter memory in the first stage and data memory in the second stage. Only the matched data in the parameter memory are compared in the data memory. This reduces the number of comparisons, thereby increasing the speed of the system. In this work dual-port RAM-based PBCAM (DP-PBCAM) is used to design a signature-based intrusion detection system. A low power parameter extractor is used with a minimum number of gates for precomputation. The hardware implementation is done using Xilinx Spartan 3E FPGA. The proposed DP-PBCAM lookups support a gigabit-speed of 7.42 Gbps.
机译:NIDS(网络入侵检测系统)在对计算机和网络的安全威胁中起着至关重要的作用。随着千兆网络的兴起,基于硬件的入侵检测系统由于其与基于软件的NIDS相比的高性能而广受欢迎。基于软件的系统限制了并行执行,从而限制了现代网络的性能。本文提出了一种使用可重配置硬件的基于签名的查找技术。内容可寻址内存(CAM)用作查找表体系结构,而不是搜索算法,可以提高速度。为了最大程度地降低功耗并提高速度,可以使用基于预计算的CAM(PBCAM),因为该技术避免了重复的搜索比较。 PBCAM采用两阶段比较,第一阶段为参数存储,第二阶段为数据存储。在数据存储器中仅比较参数存储器中的匹配数据。这减少了比较次数,从而提高了系统速度。在这项工作中,基于双端口RAM的PBCAM(DP-PBCAM)用于设计基于签名的入侵检测系统。低功率参数提取器与最少数量的门一起用于预计算。硬件实现使用Xilinx Spartan 3E FPGA完成。提议的DP-PBCAM查找支持7.42 Gbps的千兆位速度。

著录项

  • 来源
    《Computers, Materials & Continua》 |2020年第3期|1097-1107|共11页
  • 作者

  • 作者单位

    KIT-Kalaignarkarunanidhi Institute of Technology Coimbatore-641402 Tamilnadu India;

    PSG College of Technology Coimbatore-641004 Tamilnadu India;

  • 收录信息
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    NIDS; FPGA; dual port RAM; CAM; PBCAM; DP-PBCAM;

    机译:NIDS;FPGA;双端口RAM;CAM;PBCAM;数码相机;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号