...
首页> 外文期刊>International Journal of Computer Network and Information Security >Increasing the Efficiency of IDS Systems by Hardware Implementation of Packet Capturing
【24h】

Increasing the Efficiency of IDS Systems by Hardware Implementation of Packet Capturing

机译:通过数据包捕获的硬件实现提高IDS系统的效率

获取原文
   

获取外文期刊封面封底 >>

       

摘要

Capturing is the first step in intrusion detection system (IDS). Having wire speed, omitting the OS from capturing process and no need for making a copy of packets from the system’s environment to the user’s environment are some of the system characteristics. If these requirements are not met, packet capture system is considered as the main bottleneck of IDS and the overall efficiency of this system will be influenced. Presence of all these three characteristics calls for utilization of hardware methods. In this paper, by using of FPGA, a line sniffing and load balancing system are designed in order to be applied in IDS systems. The main contribution of our work is the feasibility of attaching labels to the beginning part of each packet, aiming at quick easy access of other IDS modules to information of each packet and also reducing workload of these modules. Packet classification in the proposed system can be configured to 2, 3, and 5 tuple, which can also be applied in IDS detection module in addition to load balancing part of this system. Load balancing module uses Hash table and its Hash function has the least flows collisions. This system is implemented on a set of virtex 6 and 7 families and is able to capture packets 100% and perform the above mentioned processes by speed of 12 Gbit/s.
机译:捕获是入侵检测系统(IDS)的第一步。具有线速功能,可以从捕获过程中省去操作系统,并且无需将数据包从系统环境复制到用户环境,这是系统的某些特征。如果不满足这些要求,则将数据包捕获系统视为IDS的主要瓶颈,并且将影响该系统的整体效率。所有这三个特征的存在要求使用硬件方法。本文利用FPGA设计了一种线路嗅探和负载均衡系统,以应用于IDS系统。我们工作的主要贡献是在每个数据包的开始部分附加标签的可行性,目的是使其他IDS模块快速轻松地访问每个数据包的信息,并减少这些模块的工作量。提议的系统中的数据包分类可以配置为2、3和5元组,除了该系统的负载平衡部分外,还可以应用在IDS检测模块中。负载平衡模块使用哈希表,并且其哈希函数具有最少的流冲突。该系统在一组virtex 6和7系列上实现,能够100%捕获数据包并以12 Gbit / s的速度执行上述过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号