An Efficient Multi-hash Pattern Matching Scheme for Intrusion Detection in FPGA-based Reconfiguring Hardware

被引:0
|
作者
Kim, Byoungkoo [1 ]
Yoon, Seungyong [1 ]
Oh, Jintae [1 ]
机构
[1] Elect & Telecommun Res Inst, Security Gateway Syst Team, 161 Gajeong Dong, Taejon 305700, South Korea
关键词
Intrusion Detection; Pattern Matching; Memory-efficiency;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many Network-based Intrusion Detection Systems (NIDSs) are developed till now to respond these network,attacks. As network technology presses forward, Gigabit Ethernet has become the actual standard for large network installations. Therefore, software solutions in developing high-speed NIDSs are increasingly impractical. It thus appears well motivated to investigate the hardware-based solutions. Although several solutions have been proposed recently, finding an efficient solution is considered as a difficult problem due to the limitations in resources such as a small memory size, as well as the growing link speed. Therefore, we propose the FPGA-based intrusion detection technique to detect and respond variant attacks on high-speed links. It was designed to fully exploit hardware parallelism to achieve real-time packet inspection, to require a small memory for storing signature. The technique is a part of our system, called ATPS (Adaptive Threat Prevention System) recently developed. Most of all, the proposed system has a novel content filtering technique called Table-driven Bottom-up Tree (TBT) for exact string matching. But, as the number of signatures to be compared is growing rapidly, the improved mechanism is required. In this paper, we present the multi-bash based TBT technique with memory-efficiency. Simulation based performance evaluations showed that the proposed technique used on-chip SRAM less than 20% of the one-hash based TBT technique.
引用
收藏
页码:199 / +
页数:3
相关论文
共 50 条
  • [21] FPGA-Based Lightweight Hardware Architecture of the PHOTON Hash Function for IoT Edge Devices
    Al-Shatari, Mohammed
    Hussin, Fawnizu Azmadi
    Abd Aziz, Azrina
    Witjaksono, Gunawan
    Xuan-Tu Tran
    IEEE ACCESS, 2020, 8 (08): : 207610 - 207618
  • [22] A FPGA-based intrusion detection system in IPv6
    Bin, He
    Fushan, Wei
    2007 INTERNATIONAL SYMPOSIUM ON COMPUTER SCIENCE & TECHNOLOGY, PROCEEDINGS, 2007, : 877 - 881
  • [23] FPGA-based intrusion detection system for 10 Gigabit Ethernet
    Katashita, Toshihiro
    Yamaguchi, Yoshinori
    Maeda, Atusi
    Toda, Kenji
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2007, E90D (12): : 1923 - 1931
  • [24] The Design of FPGA-Based Real Time Intrusion Detection NIC
    Cheng, Bingyuan
    Qiu, Kaijin
    Yang, Zuyong
    INFORMATION TECHNOLOGY FOR MANUFACTURING SYSTEMS II, PTS 1-3, 2011, 58-60 : 2585 - 2591
  • [25] FPGA-Based Neuro-Architecture Intrusion Detection System
    Hassan, A. A.
    Elnakib, A.
    Abo-Elsoud, M.
    ICCES: 2008 INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING & SYSTEMS, 2007, : 268 - 273
  • [26] Energy-Efficient CPU plus FPGA-Based CNN Architecture for Intrusion Detection Systems
    Maciel, Lucas A.
    Souza, Matheus A.
    Freitas, Henrique C.
    IEEE CONSUMER ELECTRONICS MAGAZINE, 2024, 13 (04) : 65 - 72
  • [27] FPGA-Based Hardware Implementation of Computationally Efficient Multi-Source DOA Estimation Algorithms
    Hussain, Ahmed A.
    Tayem, Nizar
    Soliman, Abdel-Hamid
    Radaydeh, Redha M.
    IEEE ACCESS, 2019, 7 : 88845 - 88858
  • [28] Research on Efficient Pattern Matching Algorithms in Intrusion Detection System
    Liu-xiaoxing
    Yu-ning
    2014 7TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION (ICICTA), 2014, : 509 - 512
  • [29] An FPGA-based Hardware Accelerator of RANSAC Algorithm for Matching of Images Feature Points
    Zhao, Ziwei
    Wang, Fei
    Ni, Qi
    2019 IEEE 13TH INTERNATIONAL CONFERENCE ON ASIC (ASICON), 2019,
  • [30] Applying cuckoo hashing for FPGA-based pattern matching in NIDS/NIPS
    Thinh, Tran Ngoc
    Kittitomkun, Surin
    Tomiyama, Shigenori
    ICFPT 2007: INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE TECHNOLOGY, PROCEEDINGS, 2007, : 121 - +