作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2008, Vol. 34 ›› Issue (20): 154-155. doi: 10.3969/j.issn.1000-3428.2008.20.056

• 安全技术 • 上一篇    下一篇

面向入侵检测的网络处理器设计

魏利华1,2,丁 辉1,2,宣军英2,刘小晶2   

  1. (1. 嘉兴学院信息工程学院,嘉兴 314001;2. 南京理工大学计算机科学与技术学院,南京 210094)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2008-10-20 发布日期:2008-10-20

Design of Network Processor for Intrusion-detection

WEI Li-hua1,2, DING Hui1,2, XUAN Jun-ying2, LIU Xiao-jing2   

  1. (1. School of Information Engineering, Jiaxing University, Jiaxing 314001; 2. School of Computer Science & Technology, Nanjing University of Science and Technology, Nanjing 210094)
  • Received:1900-01-01 Revised:1900-01-01 Online:2008-10-20 Published:2008-10-20

摘要: 网络速度快速提升、网络协议日新月异、攻击种类层出不穷,传统的基于软件的IDS检测速度已不胜任千兆以上网络。该文引入网络处理器技术,以硬件代替软件实现关键算法,解决了入侵检测中的速度瓶颈问题。设计了一个面向入侵检测的高速网络处理器原型,仿真实验表明其检测速度为原系统的107.36倍。

关键词: 入侵检测, 网络处理器, 模式匹配, 硬件实现

Abstract: Due to the fast increasing wire-speed of the network and the various new network protocols as well as the emerging of diversified attacks, an Intrusion Detection System(IDS) has to check more and more packages getting through the Internet. The former IDS based on software, being too slow to capture all the passing packages, are not valid in such high-speed network as Gb/s any longer. In order to solve the speed bottleneck problem for an IDS, a new network processor technique is introduced to achieve a high-speed IDS prototype by using hardware instead of software. The simulation study shows that the packets-checking speed of the newly constructed IDS is 107.36 times as that of the former IDS.

Key words: intrusion detection, network processor, pattern matching, hardware implementation

中图分类号: