首页> 外文期刊>IEICE Transactions on Information and Systems >Fpga-based Intrusion Detection System For 10 Gigabit Ethernet
【24h】

Fpga-based Intrusion Detection System For 10 Gigabit Ethernet

机译:基于FPGA的10 Gb以太网入侵检测系统

获取原文
获取原文并翻译 | 示例
       

摘要

The present paper describes an implementation of an intrusion detection system (IDS) on an FPGA for 10 Gigabit Ethernet. The system includes an exact string matching circuit for 1,225 Snort rules on a single device. A number of studies have examined string matching circuits for IDS. However, implementing a circuit that processes a large rule set at high throughput is difficult. In a previous study, we proposed a method for generating an NFA-based string matching circuit that has expandability of processing data width and drastically reduced resource requirements. In the present paper, we implement an IDS circuit that processes 1,225 Snort rules at 10 Gbps with a single Xilinx Virtex-II Pro xc2vp-100 using the NFA-based method. The proposed circuit also provides packet filtering for an intrusion protection system (IPS). In addition, we developed a tool for automatically generating the Verilog HDL source code of the IDS circuit from a Snort rule set. Using the FPGA and the IDS circuit generator, the proposed system is able to update the matching rules corresponding to new intrusions and attacks. We implemented the IDS circuit on an FPGA board and evaluated its accuracy and throughput. As a result, we confirmed in a test that the circuit detects attacks perfectly at the wire speed of 10 Gigabit Ethernet.
机译:本文介绍了一种用于10 Gb以太网的FPGA上的入侵检测系统(IDS)的实现。该系统在单个设备上包含一个精确的字符串匹配电路,可用于1,225个Snort规则。许多研究已经检查了IDS的字符串匹配电路。然而,实现以高吞吐量处理大规则集的电路是困难的。在先前的研究中,我们提出了一种用于生成基于NFA的字符串匹配电路的方法,该方法具有可扩展的数据宽度处理能力,并大大减少了资源需求。在本文中,我们使用基于NFA的方法,使用单个Xilinx Virtex-II Pro xc2vp-100实现了一个IDS电路,该电路以10 Gbps的速度处理1,225个Snort规则。所提出的电路还为入侵保护系统(IPS)提供了数据包过滤。此外,我们开发了一种工具,用于根据Snort规则集自动生成IDS电路的Verilog HDL源代码。通过使用FPGA和IDS电路生成器,所提出的系统能够更新与新的入侵和攻击相对应的匹配规则。我们在FPGA板上实现了IDS电路,并评估了其准确性和吞吐量。结果,我们在测试中确认该电路能够以10 Gb以太网的线速完美检测攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号