期刊文献+

一个千兆网络入侵防御系统的设计与实现 被引量:2

Design and Implementation of a Gigabit Rate Network Intrusion Prevention System
下载PDF
导出
摘要 随着网络速度的日益提高和网络入侵行为的越来越复杂化,高速高性能的网络入侵检测和防御系统越来越受到重视,但是目前绝大部分研究都集中在网络入侵检测系统方面.但是由于入侵检测系统的局限性,同时不具有实时阻断的功能,目前入侵防御技术和系统更受人们的重视.由于入侵防御系统涉及很多关键技术和技术难点,因此目前千兆级的实用的入侵防御系统并不多见,论文提出了一个实现网络入侵防御系统的基于硬件的框架,这个框架实现了网络入侵防御系统的所有功能.测试表明具有实用性. With the improvement of network speed and the more complicated of network intrusion behavior, high speed and high performance network intrusion detection and prevention systems are more and more needed, but most of researches and developments are focused on network intrusion detection systems now. Because of the shortcoming of network intrusion detection system and the advantage of network prevention with real time blocking, network prevention system is more and more welcome and needed. However, network prevention system includes a lot of key technologies and difficulties, practical Gigabit network prevention systems are handful on the market. In this paper, a hardware-based framework for implementing network intrusion prevention system is presented, this framework integrates and implements the functionality of network prevention system.
出处 《小型微型计算机系统》 CSCD 北大核心 2006年第11期2025-2029,共5页 Journal of Chinese Computer Systems
关键词 入侵检测 入侵防御 内容匹配 intrusion detection intrusion prevention content Matching
  • 相关文献

参考文献19

  • 1VanDyke Software(tm).Survey Shows How IT Perceives & Responds To Constantly Changing Security Threats[EB/OL].March 4,2003,http://www.vandyke.com 被引量:1
  • 2David V.Schuehler and John W.Lockwood.A modular system for FPGA-based TCP flow processing in high-speed networks[C].In Field Programmable Logic and Application:14th International Conference,FPL 2004,Leuven,Belgium,August 30-September 1,2004.Proceedings,Antwerp,Belgium,Aug.2004,301-310,Springer-Verlag. 被引量:1
  • 3David Nguyen,Joseph Zambreno,and Gokhan Memik.Flow monitoring in high-speed networks with 2D hash tables[C].In Field Programmable Logic and Application:14th International Conference,FPL 2004,Leuven,Belgium,August 30-September 1,2004.Proceedings,Antwerp,Belgium,Aug.2004,1093-1097,Springer-Verlag. 被引量:1
  • 4Marc Necker,Didier Contis,and David Schimmel.TCP-stream reassembly and state tracking in hardware[J].In IEEE Symposium on Field-Programmable Custom Computing Machines (FCCM),Napa,CA,Apr.2002,286. 被引量:1
  • 5Andy Currid.TCP offload to the rescue[J].Queue,2004,2(3):58-65. 被引量:1
  • 6Katz R,Yu F.Efficient multi-match packet classification and lookup with TCAM[C].In 12th Annual Proceedings of IEEE Hot Interconnects,Stanford,CA,Aug.2004,0-1. 被引量:1
  • 7Haoyu Song and John Lockwood.Efficient packet classification for network intrusion detection using FPGA[C].In IEEE Internation Symposium on Field-Programmable Gate Arrays,(FPGA'05),Monterey,CA,Feb.2005,pp.238-245. 被引量:1
  • 8Zheng K,Che H,Wang Z,etal.TCAM-based Distributed Parallel Packet Classification Algorithm with Range-Matching Solution[C].Proc.of IEEE INFOCOM,Volume 1,13-17 March 2005 Page(s):293-303 vol.1. 被引量:1
  • 9Roesch M.Snort:Lightweight intrusion detection for networks[C].In Proceedings of the 1999 USENIX LISA Systems Administration Conference,November 1999.(softwareavailable from http://www.snort.org/). 被引量:1
  • 10Fisk M,Varghese G.An analysis of fast string matching applied to content-based forwarding and intrusion detection[R].Technical Report CS2001-0670(updated version),University of California-San Diego,2002. 被引量:1

同被引文献28

引证文献2

二级引证文献4

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部