首页> 外国专利> Two-stage intrusion detection system for high-speed packet processing using network processor and method thereof

Two-stage intrusion detection system for high-speed packet processing using network processor and method thereof

机译:使用网络处理器的高速数据包处理的二级入侵检测系统及其方法

摘要

A system and method for detecting network intrusion by using a network processor are provided. The intrusion detection system includes: a first intrusion detector, configured to use a first network processor to perform intrusion detection on layer 3 and layer 4 of a protocol field among information included in a packet header of a packet transmitted to the intrusion detection system, and when no intrusion is detected, classify the packets according to stream and transmit the classified packets to a second intrusion detector; and a second intrusion detector, configured to use a second network processor to perform intrusion detection through deep packet inspection (DPI) for the packet payload of the packets transmitted from the first intrusion detector. Thereby, intrusion detection for high-speed packets can be performed in a network environment.
机译:提供了一种通过使用网络处理器来检测网络入侵的系统和方法。所述入侵检测系统包括:第一入侵检测器,被配置为使用第一网络处理器对包括在传输到所述入侵检测系统的分组的分组报头中的信息之中的协议字段的第3层和第4层执行入侵检测;以及当没有检测到入侵时,根据流对报文进行分类,并将分类后的报文发送给第二入侵检测器;第二入侵检测器,用于使用第二网络处理器对从所述第一入侵检测器发送来的分组的分组净荷进行深度分组检测(DPI)来进行入侵检测。从而,可以在网络环境中执行针对高速分组的入侵检测。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号