Flexible software-hardware Network Intrusion Detection System

被引:3
|
作者
Proudfoot, Ryan [1 ]
Kent, Kenneth [1 ]
Aubanel, Eric [1 ]
Chen, Nan [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Fredericton, NB E3B 5A3, Canada
关键词
D O I
10.1109/RSP.2008.11
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Network Intrusion Detection System (NIDS) demands have been steadily increasing over the past few years. Current solutions using software become inefficient running on high speed high volume networks and will end up dropping packets. Hardware solutions are available and result in much higher efficiency but present problems such as flexibility and cost. Our proposed system uses a modified version of Snort, a robust widely deployed open-sourced NIDS. Snort spends a significant fraction of its processing time doing pattern matching. Our proposed system runs Snort in software until it gets to the pattern matching function and then offloads that processing to the Field Programmable Gate Array (FPGA). The hardware is able to process data at up to 1.7GB/s on one Xilinx XC2VP100 FPGA. Our system is more flexible than other FPGA string matching designs in that the rules are not hard-coded. The design is scalable and allows FPGAs to be used in parallel to increase the processing speed even further.
引用
收藏
页码:182 / 188
页数:7
相关论文
共 50 条
  • [21] Flexible Network-based Intrusion Detection and Prevention System on Software-defined Networks
    An Le
    Phuong Dinh
    Hoa Le
    Ngoc Cuong Tran
    2015 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTING AND APPLICATIONS (ACOMP), 2015, : 106 - 111
  • [22] A Software-Hardware collaboration system for CNN algorithms based on FPGA
    Zhao, Shuo
    Zhang, Kunning
    Fan, Jun
    He, Hu
    2019 IEEE INTERNATIONAL CONFERENCE ON ELECTRON DEVICES AND SOLID-STATE CIRCUITS (EDSSC), 2019,
  • [23] A software-hardware system of remote monitoring and analysis of the energy data
    Lyakhomskii A.V.
    Perfil’eva E.N.
    Kychkin A.V.
    Genrikh N.
    Russian Electrical Engineering, 2015, 86 (06) : 314 - 319
  • [24] Architecture of an Integrated Software-Hardware System for Accelerated Image Processing
    Cyganek, Boguslaw
    COMPUTER VISION AND GRAPHICS, 2009, 5337 : 1 - 13
  • [25] Synthetical reliability analysis of PLC control system software-hardware
    School of Computer Science and Engineering, Wenzhou University, Wenzhou 325035, China
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2008, 14 (07): : 1399 - 1402
  • [26] A versatile software-hardware system for environmental data acquisition and transmission
    Zappala, G.
    COMPUTATIONAL METHODS AND EXPERIMENTAL MEASUREMENTS XIV, 2009, 48 : 283 - 294
  • [27] Software-hardware cooperative memory disambiguation
    Huang, Ruke
    Garg, Alok
    Huang, Michael
    TWELFTH INTERNATIONAL SYMPOSIUM ON HIGH-PERFORMANCE COMPUTER ARCHITECTURE, PROCEEDINGS, 2006, : 248 - +
  • [28] The software-hardware simulator of the electric drive
    Ziuzev, A. M.
    Nesterov, K. E.
    Mudrov, M., V
    2014 16TH EUROPEAN CONFERENCE ON POWER ELECTRONICS AND APPLICATIONS (EPE'14-ECCE EUROPE), 2014,
  • [29] Software-Hardware Mapping in a Robot Design
    Jusko, Pavol
    Obdrzalek, David
    Petrusek, Tomas
    RESEARCH AND EDUCATION IN ROBOTICS - EUROBOT 2008, 2009, 33 : 19 - 28
  • [30] DIAGNOSIS INFRASTRUCTURE FOR SOFTWARE-HARDWARE SYSTEMS
    Hahanov, V. I.
    Chumachenko, S. V.
    Litvinova, E. I.
    Guz, O. A.
    RADIO ELECTRONICS COMPUTER SCIENCE CONTROL, 2012, 1 : 134 - 140