首页> 外文OA文献 >A MULTI-GIGABIT NETWORK PACKET INSPECTION AND ANALYSIS ARCHITECTURE FOR INTRUSION DETECTION AND PREVENTION UTILIZING PIPELINING AND CONTENT-ADDRESSABLE MEMORY
【2h】

A MULTI-GIGABIT NETWORK PACKET INSPECTION AND ANALYSIS ARCHITECTURE FOR INTRUSION DETECTION AND PREVENTION UTILIZING PIPELINING AND CONTENT-ADDRESSABLE MEMORY

机译:利用管道和可寻址内容的内存进行入侵检测和预防的多千兆位网络数据包检查和分析架构

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Increases in network traffic volume and transmission speeds have given rise to the need for extremely fast packet processing. Many traditional processor-based network devices are no longer sufficient to handle tasks such as packet analysis and intrusion detection at multi-Gigabit rates. This thesis proposes two novel pipelined hardware architectures to relieve the computational load of a processor within network switches and routers. First, the Embedded Protocol Analyzer Pre-Processor (ePAPP) is capable of taking an unclassified packet byte stream directly off of a network cable at line speed and separating the data into individually classified protocol fields. Second, the CAM-Assisted Signature-Matching Architecture (CASMA) uses ternary content-addressable memory to perform the task of stateless intrusion detection signature-matching. The Snort open-source software network intrusion detection system is used as a model for intrusion detection functionality. Structured ASIC synthesis results show that ePAPP supports speeds of 2.89 Gb/s using less than 1% of available logic cells. CASMA is shown to support 1.25 Gb/s using less than 6% of available logic cells. The CASMA architecture is demonstrated to be able to implement 1729 of 1993 or 86.8% of the attack signatures, or rules, packaged with Snort version 2.1.2.
机译:网络业务量和传输速度的增加已经引起对极其快速的分组处理的需求。许多传统的基于处理器的网络设备已不足以以千兆位速率处理数据包分析和入侵检测等任务。本文提出了两种新颖的流水线硬件架构,以减轻网络交换机和路由器中处理器的计算负荷。首先,嵌入式协议分析器预处理器(ePAPP)能够以线速直接从网络电缆中提取未分类的分组字节流,并将数据分成单独分类的协议字段。其次,CAM辅助签名匹配体系结构(CASMA)使用三态内容可寻址存储器来执行无状态入侵检测签名匹配的任务。 Snort开源软件网络入侵检测系统用作入侵检测功能的模型。结构化的ASIC综合结果表明,使用不到1%的可用逻辑单元,ePAPP支持的速度为2.89 Gb / s。事实证明,CASMA使用不到6%的可用逻辑单元即可支持1.25 Gb / s。事实证明,CASMA体系结构能够实现1993年的1729年或与Snort版本2.1.2打包在一起的攻击签名或规则的86.8%。

著录项

  • 作者

    Repanshek Jacob J.;

  • 作者单位
  • 年度 2005
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号