Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems
碩士 === 國立海洋大學 === 電機工程學系 === 91 === The main purpose of an intrusion detection system (IDS) is to monitor the traffics on the network, sniff out malicious activities, block attacks on the computers, and alert the system administrators when necessary. A well-known example of the IDS is S...
Main Authors: | , |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Published: |
2003
|
Online Access: | http://ndltd.ncl.edu.tw/handle/85349675616572811987 |
id |
ndltd-TW-091NTOU0442025 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-091NTOU04420252016-06-22T04:26:45Z http://ndltd.ncl.edu.tw/handle/85349675616572811987 Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems 網路入侵偵測系統之多樣式比對器設計與實現 Szu-Yuan Peng 彭思淵 碩士 國立海洋大學 電機工程學系 91 The main purpose of an intrusion detection system (IDS) is to monitor the traffics on the network, sniff out malicious activities, block attacks on the computers, and alert the system administrators when necessary. A well-known example of the IDS is Snort, a freeware which uses misuse detection to sense network intrusions. The detection is primarily based on pattern matching for the contents of the incoming packets. A match with any of the predetermined string patterns signifies a potential intrusion attempt. Pattern matching operations are highly CPU-bound and require a large amount of memory accesses. When the network traffic is heavy, a certain amount of packets are likely to elude the screening of Snort. To facilitate the pattern matching operations of an IDS, we propose in this thesis a multi-pattern matching hardware architecture. For performance considerations, we adopt the Aho-Corasick algorithm for pattern matching and use binary search to reduce memory references. The hardware is implemented with a VHDL-based FPGA design flow emphasizing design scalability and reusability. On our current FPGA platform, the circuit operates at a baud rate of 500 kByte/s, which is suitable for most ADSL applications. For high-speed network environments, our design allows easy multiplication into a parallel pattern-matching engine and will be able to provide performance enhancements required for a variety of applications. Shao-Wei Leu 呂紹偉 2003 學位論文 ; thesis 40 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立海洋大學 === 電機工程學系 === 91 === The main purpose of an intrusion detection system (IDS) is to monitor the traffics on the network, sniff out malicious activities, block attacks on the computers, and alert the system administrators when necessary. A well-known example of the IDS is Snort, a freeware which uses misuse detection to sense network intrusions. The detection is primarily based on pattern matching for the contents of the incoming packets. A match with any of the predetermined string patterns signifies a potential intrusion attempt. Pattern matching operations are highly CPU-bound and require a large amount of memory accesses. When the network traffic is heavy, a certain amount of packets are likely to elude the screening of Snort. To facilitate the pattern matching operations of an IDS, we propose in this thesis a multi-pattern matching hardware architecture. For performance considerations, we adopt the Aho-Corasick algorithm for pattern matching and use binary search to reduce memory references. The hardware is implemented with a VHDL-based FPGA design flow emphasizing design scalability and reusability. On our current FPGA platform, the circuit operates at a baud rate of 500 kByte/s, which is suitable for most ADSL applications. For high-speed network environments, our design allows easy multiplication into a parallel pattern-matching engine and will be able to provide performance enhancements required for a variety of applications.
|
author2 |
Shao-Wei Leu |
author_facet |
Shao-Wei Leu Szu-Yuan Peng 彭思淵 |
author |
Szu-Yuan Peng 彭思淵 |
spellingShingle |
Szu-Yuan Peng 彭思淵 Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems |
author_sort |
Szu-Yuan Peng |
title |
Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems |
title_short |
Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems |
title_full |
Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems |
title_fullStr |
Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems |
title_full_unstemmed |
Design and Implementation of a Multi-Pattern Matching Circuit for Intrusion Detection Systems |
title_sort |
design and implementation of a multi-pattern matching circuit for intrusion detection systems |
publishDate |
2003 |
url |
http://ndltd.ncl.edu.tw/handle/85349675616572811987 |
work_keys_str_mv |
AT szuyuanpeng designandimplementationofamultipatternmatchingcircuitforintrusiondetectionsystems AT péngsīyuān designandimplementationofamultipatternmatchingcircuitforintrusiondetectionsystems AT szuyuanpeng wǎnglùrùqīnzhēncèxìtǒngzhīduōyàngshìbǐduìqìshèjìyǔshíxiàn AT péngsīyuān wǎnglùrùqīnzhēncèxìtǒngzhīduōyàngshìbǐduìqìshèjìyǔshíxiàn |
_version_ |
1718320338621693952 |