期刊文献+

基于SOPC网络处理器入侵检测的研究

Research of Intrusion Detection Based on SOPC Network Processor
下载PDF
导出
摘要 在入侵检测中,模式匹配算法的改进对检测速度的提高是有限的,不是解决问题的根本策略。本文设计了一个基于硬件的入侵检测系统原型,系统采用基于网络处理器的硬件策略取代传统入侵检测的软件策略,将入侵检测的主要工作,如数据采集及过滤、数据包的调度、多模式匹配等用硬件实现。它们都是在基于FPGA上实现的,并可以根据实际需要增加硬件和自定义指令来提高系统性能。测试表明该系统的性能与传统方法相比有显著的提高,很好地解决了入侵检测中的速度瓶颈问题。 In intrusion detection, improvement of the pattern-matching algorithms is limited to the increase of detection rate and not fundamental strategy to solve the problem. This paper designed intrusion detection system prototype based on the hardware. The system uses hardware implementations based on network processor to replace the traditional software strategy and uses hardware to realize the main functions such as data-collecting and filtering, data-packets dispatching, multi-patterns matching. They are completed based on the FPGA, and we may add the hardware and define our specific instructions to accelerate system performance. Experimental shows that the system's performance has a significant improvement compared to traditional methods, and is a good solution to the bottlenecks of intrusion detection speed.
作者 孙海军 高岩
出处 《微计算机信息》 2009年第23期143-144,147,共3页 Control & Automation
关键词 SOPC 入侵检测 模式匹配 网络处理器 SOPC Intrusion detection Pattern matching Network processor
  • 相关文献

参考文献4

二级参考文献53

  • 1彭保,范婷婷,马建国.基于Verilog HDL语言的FPGA设计[J].微计算机信息,2004,20(10):80-82. 被引量:16
  • 2[4]从 FPGA 到 SOPC.www.21control.com. 被引量:1
  • 3[5]Texas Instruments Corporation.TLV5580 Datasheet. 被引量:1
  • 4[6]Altera Corporation.Cyclone FPGA Family Data Sheet. 被引量:1
  • 5[7]Cypress Semiconductor Corporation.CY7C68013 Datasheet. 被引量:1
  • 6彭澄廉,周博,邱卫东,等.挑战SOC[M].2004.7. 被引量:2
  • 7LEE W,STOLFO S,MOK K. A data mining framework for adaptive intrusion detection[EB/OL]. http://www.cs.columbia.edu/~sal/ hpapers/framework.ps.gz. 被引量:1
  • 8LEE W, STOLFO S J, MOK K. Algorithms for mining system audit data[EB/OL]. http://citeseer.ist.psu.edu/lee99algorithms.html. 1999. 被引量:1
  • 9KRUEGEL C, TOTH T, KIRDA E.Service specific anomaly detection for network intrusion detection[A]. Proceedings of the 2002 ACM Symposium on Applied Computing[C]. Madrid, Spain, 2002. 201-208. 被引量:1
  • 10LIAO Y, VEMURI V R. Use of text categorization techniques for intrusion detection[A]. 11th USENIX Security Symposium[C]. San Francisco, CA, 2002. 被引量:1

共引文献243

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部