An Efficient Multi-hash Pattern Matching Scheme for Intrusion Detection in FPGA-based Reconfiguring Hardware

被引:0
作者
Kim, Byoungkoo [1 ]
Yoon, Seungyong [1 ]
Oh, Jintae [1 ]
机构
[1] Elect & Telecommun Res Inst, Security Gateway Syst Team, 161 Gajeong Dong, Taejon 305700, South Korea
来源
PROCEEDINGS OF THE 8TH WSEAS INTERNATIONAL CONFERENCE ON APPLIED COMPUTER SCIENCE (ACS'08): RECENT ADVANCES ON APPLIED COMPUTER SCIENCE | 2008年
关键词
Intrusion Detection; Pattern Matching; Memory-efficiency;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many Network-based Intrusion Detection Systems (NIDSs) are developed till now to respond these network,attacks. As network technology presses forward, Gigabit Ethernet has become the actual standard for large network installations. Therefore, software solutions in developing high-speed NIDSs are increasingly impractical. It thus appears well motivated to investigate the hardware-based solutions. Although several solutions have been proposed recently, finding an efficient solution is considered as a difficult problem due to the limitations in resources such as a small memory size, as well as the growing link speed. Therefore, we propose the FPGA-based intrusion detection technique to detect and respond variant attacks on high-speed links. It was designed to fully exploit hardware parallelism to achieve real-time packet inspection, to require a small memory for storing signature. The technique is a part of our system, called ATPS (Adaptive Threat Prevention System) recently developed. Most of all, the proposed system has a novel content filtering technique called Table-driven Bottom-up Tree (TBT) for exact string matching. But, as the number of signatures to be compared is growing rapidly, the improved mechanism is required. In this paper, we present the multi-bash based TBT technique with memory-efficiency. Simulation based performance evaluations showed that the proposed technique used on-chip SRAM less than 20% of the one-hash based TBT technique.
引用
收藏
页码:199 / +
页数:3
相关论文
共 14 条
[1]   EFFICIENT STRING MATCHING - AID TO BIBLIOGRAPHIC SEARCH [J].
AHO, AV ;
CORASICK, MJ .
COMMUNICATIONS OF THE ACM, 1975, 18 (06) :333-340
[2]  
ALDWAIRI M, 2005, ACM SIGARCH COMPUTER, V33, P99
[3]   FAST STRING SEARCHING ALGORITHM [J].
BOYER, RS ;
MOORE, JS .
COMMUNICATIONS OF THE ACM, 1977, 20 (10) :762-772
[4]  
Cho Y. H., 2002, P INT C FIELD PROGR
[5]  
DEBAR H, 1998, 3030 RZ ZUR RES LAB
[6]  
Kim B, 2007, LECT NOTES COMPUT SC, V4773, P344
[7]   Stateful intrusion detection for high-speed networks [J].
Kruegel, C ;
Valeur, F ;
Vigna, G ;
Kemmerer, R .
2002 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2002, :285-293
[8]  
Kumar Sandeep., 1994, P 17 NATL COMPUTER S, P11
[9]  
MOSCOLA J, 2003, IEEE S FIELD PROGR C
[10]  
Ptacek T. H., 1998, P CEUR WORKSH