首页> 外国专利> Intrusion detection using a network processor and a parallel pattern detection engine

Intrusion detection using a network processor and a parallel pattern detection engine

机译:使用网络处理器和并行模式检测引擎的入侵检测

摘要

An intrusion detection system (IDS) comprises a network processor (NP) coupled to a memory unit for storing programs and data. The NP is also coupled to one or more parallel pattern detection engines (PPDE) which provide high speed parallel detection of patterns in an input data stream. Each PPDE comprises many processing units (PUs) each designed to store intrusion signatures as a sequence of data with selected operation codes. The PUs have configuration registers for selecting modes of pattern recognition. Each PU compares a byte at each clock cycle. If a sequence of bytes from the input pattern match a stored pattern, the identification of the PU detecting the pattern is outputted with any applicable comparison data. By storing intrusion signatures in many parallel PUs, the IDS can process network data at the NP processing speed. PUs may be cascaded to increase intrusion coverage or to detect long intrusion signatures.
机译:入侵检测系统(IDS)包括连接到用于存储程序和数据的存储单元的网络处理器(NP)。 NP还与一个或多个并行模式检测引擎(PPDE)耦合,该引擎可对输入数据流中的模式进行高速并行检测。每个PPDE都包含许多处理单元(PU),每个处理单元设计用于将入侵签名存储为具有选定操作代码的数据序列。 PU具有用于选择模式识别模式的配置寄存器。每个PU在每个时钟周期比较一个字节。如果来自输入模式的字节序列与存储的模式匹配,则检测模式的PU的标识与任何适用的比较数据一起输出。通过将入侵签名存储在许多并行的PU中,IDS可以NP处理速度处理网络数据。 PU可以级联以增加入侵范围或检测长入侵特征。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号