A pattern matching co-processor for network security

被引:0
作者
Cho, YH [1 ]
Mangione-Smith, WH [1 ]
机构
[1] Univ Calif Los Angeles, Dept Elect Engn, Los Angeles, CA 90024 USA
来源
42ND DESIGN AUTOMATION CONFERENCE, PROCEEDINGS 2005 | 2005年
关键词
network security; intrusion; pattern matching; pattern search; snort;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
It has been estimated that computer network worms and virus caused the loss of over $5513 in 2003. Network security system use techniques such as deep packet inspection to detect the harmful packets. While software intrusion detection system running on general purpose processors can be updated in response to new attacks. They lack the processing power to monitor gigabit networks. We present a high performance pattern matching co-processor architecture that can be used to monitor and identify a large number of intrusion signature. The design consists of a bank of pattern matchers that are used to implement a highly concurrent filter. The pattern matchers can be programmed to match multiple patterns of various lengths, and are able to leverage the existing databases of threat signatures. We have been able to program the filters to match all the payload patterns defined in the widely used Snort network intrusion detection system at a rate above 7 Gbps, with memory space left to accommodate threat signatures that become available in the future.
引用
收藏
页码:234 / 239
页数:6
相关论文
共 14 条
[11]  
Sidhu R., 2001, FIELD PROGR CUST COM
[12]  
WATSON D, 2004, IEEE ACM T NETW APR
[13]  
YOUNG H, 2002, 12 C FIELD PROGR LOG, P452
[14]  
YOUNG H, 2004, IEEE S FIELD PROGR C