首页> 外文期刊>Journal of Signal Processing Systems >Variable Length Pattern Matching for Hardware Network Intrusion Detection System
【24h】

Variable Length Pattern Matching for Hardware Network Intrusion Detection System

机译:硬件网络入侵检测系统的可变长度模式匹配

获取原文
获取原文并翻译 | 示例

摘要

With the wide adoption of internet into our everyday lives, internet security becomes an important issue. Intrusion detection at the network level is an effective way of stopping malicious attacks at the source and preventing viruses and worms from wide spreading. The key component in a successful network intrusion detection system is a high performance pattern matching engine that can uncover the malicious activities in real time. In this paper, we propose a highly parallel, scalable hardware based network intrusion detection system, that can handle variable pattern length efficiently and effectively. Pattern matching for a packet is completed in O(N log M) time where N is the size of the packet and M is the longest pattern length. Implementation is done on a standard off-the-shelf field-programmable gate array. Comparison with the other techniques shows promising results.
机译:随着互联网在我们日常生活中的广泛采用,互联网安全已成为一个重要问题。在网络级别进行入侵检测是从源头阻止恶意攻击并防止病毒和蠕虫广泛传播的有效方法。成功的网络入侵检测系统的关键组件是高性能模式匹配引擎,可以实时发现恶意活动。在本文中,我们提出了一种高度并行,可扩展的基于硬件的网络入侵检测系统,该系统可以有效地处理可变模式长度。数据包的模式匹配在O(N log M)时间内完成,其中N是数据包的大小,M是最长的模式长度。实现是在标准的现成现场可编程门阵列上完成的。与其他技术的比较显示出可喜的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号