An Efficient Multi-hash Pattern Matching Scheme for Intrusion Detection in FPGA-based Reconfiguring Hardware

被引:0
|
作者
Kim, Byoungkoo [1 ]
Yoon, Seungyong [1 ]
Oh, Jintae [1 ]
机构
[1] Elect & Telecommun Res Inst, Security Gateway Syst Team, 161 Gajeong Dong, Taejon 305700, South Korea
关键词
Intrusion Detection; Pattern Matching; Memory-efficiency;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many Network-based Intrusion Detection Systems (NIDSs) are developed till now to respond these network,attacks. As network technology presses forward, Gigabit Ethernet has become the actual standard for large network installations. Therefore, software solutions in developing high-speed NIDSs are increasingly impractical. It thus appears well motivated to investigate the hardware-based solutions. Although several solutions have been proposed recently, finding an efficient solution is considered as a difficult problem due to the limitations in resources such as a small memory size, as well as the growing link speed. Therefore, we propose the FPGA-based intrusion detection technique to detect and respond variant attacks on high-speed links. It was designed to fully exploit hardware parallelism to achieve real-time packet inspection, to require a small memory for storing signature. The technique is a part of our system, called ATPS (Adaptive Threat Prevention System) recently developed. Most of all, the proposed system has a novel content filtering technique called Table-driven Bottom-up Tree (TBT) for exact string matching. But, as the number of signatures to be compared is growing rapidly, the improved mechanism is required. In this paper, we present the multi-bash based TBT technique with memory-efficiency. Simulation based performance evaluations showed that the proposed technique used on-chip SRAM less than 20% of the one-hash based TBT technique.
引用
收藏
页码:199 / +
页数:3
相关论文
共 50 条
  • [31] An FPGA-based implementation of corner detection and matching with outlier rejection
    Huang, Jingjin
    Zhou, Guoqing
    Zhang, Dianjun
    Zhang, Guangyun
    Zhang, Rongting
    Baysal, Oktay
    INTERNATIONAL JOURNAL OF REMOTE SENSING, 2018, 39 (23) : 8905 - 8933
  • [32] An Efficient Compression Scheme for Checkpointing of FPGA-Based Digital Mockups
    Chou, Ting-Shuo
    Givargis, Tony
    Huang, Chen
    Miller, Bailey
    Vahid, Frank
    2013 18TH ASIA AND SOUTH PACIFIC DESIGN AUTOMATION CONFERENCE (ASP-DAC), 2013, : 632 - 637
  • [33] An improved multi-pattern matching algorithms in intrusion detection
    Cheng Ke-qin
    Deng Lin
    Wang Hui
    2013 FIFTH INTERNATIONAL CONFERENCE ON MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION (ICMTMA 2013), 2013, : 203 - 205
  • [34] Architecture and Mechanisms for Implementing an FPGA-based Stateful Intrusion Detection System
    Oh, Jin-Tae
    Kim, Byoung-Koo
    Yoon, Seung-Yong
    Jang, Jong-Soo
    Jeon, Yong-Hee
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (05): : 110 - 117
  • [35] A pattern matching based network intrusion detection system
    Zhou Chunyue
    Liu Yun
    Zhang Hongke
    2006 9TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION, VOLS 1- 5, 2006, : 1410 - +
  • [36] Fast FPGA-based delay estimation for a novel hardware/software partitioning scheme
    Abdelhalim, M. B.
    Habib, S. E. -D.
    IDT 2007: SECOND INTERNATIONAL DESIGN AND TEST WORKSHOP, PROCEEDINGS, 2007, : 175 - 181
  • [37] An Efficient Implementation of FPGA-based Object Detection Using Multi-scale Attention
    Furuta, Masanori
    Ban, Koichiro
    Kobayashi, Daisuke
    Shibata, Tomoyuki
    2021 IEEE INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2021, : 321 - 325
  • [38] FPGA-based hardware-in-the-loop for multi-domain simulation
    Benhamadouche, Abdelouahab D.
    Djahli, Farid
    Ballouti, Adel
    Sahli, Abdeslem
    INTERNATIONAL JOURNAL OF MODELING SIMULATION AND SCIENTIFIC COMPUTING, 2019, 10 (04)
  • [39] FPGA-based Flexible Hardware Architecture for Image Interest Point Detection
    Hernandez-Lopez, Ana
    Torres-Huitzil, Cesar
    Garcia-Hernandez, Jose Juan
    INTERNATIONAL JOURNAL OF ADVANCED ROBOTIC SYSTEMS, 2015, 12
  • [40] Single Digit Hash Boyer Moore Horspool Pattern Matching Algorithm for Intrusion Detection System
    Sharma, Sakshi
    Dixit, Manish
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2016, 9 (09): : 169 - 180