An FPGA-based network intrusion detection system with on-chip network interfaces

被引:10
作者
Clark, C. R. [1 ]
Ulmer, C. D.
Schimmel, D. E.
机构
[1] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
[2] Sandia Natl Labs, Livermore, CA USA
关键词
field-programmable gate array (FPGA); intrusion detection; pattern-matching; Gigabit Ethernet;
D O I
10.1080/00207210600566083
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Network intrusion detection systems (NIDS) are critical network security tools that help protect computer installations from malicious users. Traditional software-based NIDS architectures are becoming strained as network data rates increase and attacks intensify in volume and complexity. In recent years, researchers have proposed using FPGAs to perform the computationally-intensive components of intrusion detection analysis. In this work, we present a new NIDS architecture that integrates the network interface hardware and packet analysis hardware into a single FPGA chip. This integration enables a higher performance and more flexible NIDS platform. To demonstrate the benefits of this technique, we have implemented a complete and functional NIDS in a Xilinx Virtex II Pro FPGA that performs in-line packet analysis and filtering on multiple Gigabit Ethernet links using rules from the open-source Snort attack database.
引用
收藏
页码:403 / 420
页数:18
相关论文
共 20 条
[1]  
[Anonymous], P 11 ANN ACM SIGDA I
[2]   A methodology for synthesis of efficient intrusion detection systems on FPGAs [J].
Baker, ZK ;
Prasanna, VK .
12TH ANNUAL IEEE SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES, PROCEEDINGS, 2004, :135-144
[3]   JHDL - An HDL for reconfigurable systems [J].
Bellows, P ;
Hutchings, B .
IEEE SYMPOSIUM ON FPGAS FOR CUSTOM COMPUTING MACHINES, PROCEEDINGS, 1998, :175-184
[4]   Deep packet filter with dedicated logic and read only memories [J].
Cho, YH ;
Mangione-Smith, WH .
12TH ANNUAL IEEE SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES, PROCEEDINGS, 2004, :125-134
[5]   Scalable pattern matching for high speed networks [J].
Clark, CR ;
Schimmel, DE .
12TH ANNUAL IEEE SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES, PROCEEDINGS, 2004, :249-257
[6]  
CLARK CR, 2004, P WORKSH NETW PROC A, P136
[7]  
Dharmapurikar S, 2003, HOT INTERCONNECTS 11, P44
[8]   Assisting network intrusion detection with reconfigurable hardware [J].
Hutchings, BL ;
Franklin, R ;
Carver, D .
10TH ANNUAL IEEE SYMPOSIUM ON FIELD-PROGRAMMABLE CUSTOM COMPUTING MACHINES, PROCEEDINGS, 2002, :111-120
[9]  
Li SM, 2003, LECT NOTES COMPUT SC, V2778, P1153
[10]  
Lockwood JW, 2003, LECT NOTES COMPUT SC, V2778, P859