首页> 外文期刊>IEEE transactions on information forensics and security >An FPGA-Based Network Intrusion Detection Architecture
【24h】

An FPGA-Based Network Intrusion Detection Architecture

机译:基于FPGA的网络入侵检测架构

获取原文
获取原文并翻译 | 示例

摘要

Network intrusion detection systems (NIDSs) monitor network traffic for suspicious activity and alert the system or network administrator. With the onset of gigabit networks, current generation networking components for NIDS will soon be insufficient for numerous reasons; most notably because the existing methods cannot support high-performance demands. Field-programmable gate arrays (FPGAs) are an attractive medium to handle both high throughput and adaptability to the dynamic nature of intrusion detection. In this work, we design an FPGA-based architecture for anomaly detection in network transmissions. We first develop a feature extraction module (FEM) which aims to summarize network information to be used at a later stage. Our FPGA implementation shows that we can achieve significant performance improvements compared to existing software and application-specific integrated-circuit implementations. Then, we go one step further and demonstrate the use of principal component analysis as an outlier detection method for NIDSs. The results show that our architecture correctly classifies attacks with detection rates exceeding 99% and false alarms rates as low as 1.95%. Moreover, using extensive pipelining and hardware parallelism, it can be shown that for realistic workloads, our architectures for FEM and outlier analysis achieve 21.25- and 23.76-Gb/s core throughput, respectively.
机译:网络入侵检测系统(NIDS)监视网络流量中是否存在可疑活动,并警告系统或网络管理员。随着千兆网络的出现,由于多种原因,用于NIDS的当前网络组件很快将不足。最明显的原因是现有方法无法满足高性能要求。现场可编程门阵列(FPGA)是一种吸引人的介质,既可以处理高吞吐量,又可以适应入侵检测的动态特性。在这项工作中,我们设计了一种基于FPGA的体系结构,用于网络传输中的异常检测。我们首先开发一个特征提取模块(FEM),其目的是汇总以后要使用的网络信息。我们的FPGA实现表明,与现有软件和专用集成电路实现相比,我们可以实现显着的性能改进。然后,我们进一步走了一步,并证明了主成分分析作为NIDS异常检测方法的用途。结果表明,我们的体系结构正确地对攻击进行了分类,检测率超过99%,错误警报率低至1.95%。此外,使用广泛的流水线技术和硬件并行性,可以证明,对于实际的工作负载,我们用于FEM和离群分析的架构分别实现了21.25-Gb和23.76-Gb / s的核心吞吐量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号