Flexible software-hardware Network Intrusion Detection System

被引:3
|
作者
Proudfoot, Ryan [1 ]
Kent, Kenneth [1 ]
Aubanel, Eric [1 ]
Chen, Nan [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Fredericton, NB E3B 5A3, Canada
关键词
D O I
10.1109/RSP.2008.11
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection System (NIDS) demands have been steadily increasing over the past few years. Current solutions using software become inefficient running on high speed high volume networks and will end up dropping packets. Hardware solutions are available and result in much higher efficiency but present problems such as flexibility and cost. Our proposed system uses a modified version of Snort, a robust widely deployed open-sourced NIDS. Snort spends a significant fraction of its processing time doing pattern matching. Our proposed system runs Snort in software until it gets to the pattern matching function and then offloads that processing to the Field Programmable Gate Array (FPGA). The hardware is able to process data at up to 1.7GB/s on one Xilinx XC2VP100 FPGA. Our system is more flexible than other FPGA string matching designs in that the rules are not hard-coded. The design is scalable and allows FPGAs to be used in parallel to increase the processing speed even further.
引用
收藏
页码:182 / 188
页数:7
相关论文
共 50 条
  • [1] High performance software-hardware network intrusion detection system
    Proudfoot, Ryan
    Kent, Kenneth
    Aubanel, Eric
    Chen, Nan
    ICFPT 2007: INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE TECHNOLOGY, PROCEEDINGS, 2007, : 309 - 312
  • [2] Kvint software-hardware system
    Kurnosov, N.M.
    Pevzner, V.V.
    Ulanov, A.G.
    Yakhin, E.A.
    Thermal Engineering (English translation of Teploenergetika), 1993, 40 (10):
  • [3] Software-hardware complexes: Towards flexible borders
    Rammig, Franz J.
    Embedded System Design: Topics, Techniques and Trends, 2007, 231 : 433 - 435
  • [4] A software-hardware selective attention system
    Carota, L
    Indiveri, G
    Dante, V
    NEUROCOMPUTING, 2004, 58 : 647 - 653
  • [5] A software-hardware selective attention system
    Carota, L
    Indiveri, G
    Dante, V
    COMPUTATIONAL NEUROSCIENCE: TRENDS IN RESEARCH 2004, 2004, : 647 - 653
  • [6] Software-Hardware System for Pulse Wave Recording
    Yavelov I.S.
    Biomedical Engineering, 2013, 46 (6) : 246 - 249
  • [7] A FORMAL REPRESENTATION OF SOFTWARE-HARDWARE SYSTEM DESIGN
    Walkingshaw, Eric
    Strauss, Paul
    Erwig, Martin
    Mueller, Jonathan
    Tumer, Irem
    ASME INTERNATIONAL DESIGN ENGINEERING TECHNICAL CONFERENCES AND COMPUTERS AND INFORMATION IN ENGINEERING CONFERENCE, PROCEEDINGS, VOL 2, PTS A AND B, 2010, : 1387 - 1398
  • [8] SOFTWARE-HARDWARE SYSTEMS
    Molchanov, I. N.
    Pereyozchikova, O. L.
    Khimich, A. N.
    CYBERNETICS AND SYSTEMS ANALYSIS, 2007, 43 (03) : 439 - 442
  • [9] Combined Reliability Test for Software-hardware System
    Huang, Linzhi
    Ai, Jun
    Wang, Jinhui
    2014 IEEE 4TH ANNUAL INTERNATIONAL CONFERENCE ON CYBER TECHNOLOGY IN AUTOMATION, CONTROL, AND INTELLIGENT SYSTEMS (CYBER), 2014, : 658 - 663
  • [10] Software-Hardware System for Measurement of the Pallet Dimensions
    Sorokin, Pavel V.
    Kostina, Maria A.
    Bortalevich, Svetlana I.
    Kozhemyak, Olesya A.
    Loginov, Evgeniy L.
    Shinyakov, Yuriy A.
    Sukhorukov, Maxim P.
    2017 INTERNATIONAL SIBERIAN CONFERENCE ON CONTROL AND COMMUNICATIONS (SIBCON) PROCEEDINGS, 2017,