作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2006, Vol. 32 ›› Issue (7): 160-162.

• 安全技术 • 上一篇    下一篇

基于网络处理器的入侵检测方法

魏利华 1,2,张晓明2,唐玉华2,孙志刚2   

  1. 1. 浙江嘉兴学院信息工程学院,嘉兴 314001;2. 国防科技大学计算机学院,长沙 410073
  • 出版日期:2006-04-05 发布日期:2006-04-05

Intrusion Detection Methods Based on Network Processor

WEI Lihua1,2, ZHANG Xiaoming2, TANG Yuhua2, SUN Zhigang2   

  1. 1. School of Information Engineering, Jiaxing University in Zhejiang Province, Jiaxing 314001;2. School of Computer, National University of Defence Technology, Changsha 410073
  • Online:2006-04-05 Published:2006-04-05

摘要: 入侵检测是网络安全的核心技术。随着网络速度的不断提升,现有NIDS 的检测速度已不适应千兆位以上网络,漏检率和误检率越来越高。网络处理器以高度并行、硬件多线程、多级存储和灵活可编程等先进技术提供高速的数据包处理性能。该文对利用网络处理器解决入侵检测的速度瓶颈提出了观点、方法和策略,设计和实现了一个面向入侵检测的高速网络处理器原型。

关键词: 网络处理器;入侵检测;多级并行;硬件线程;调度策略

Abstract: Intrusion detection is a dynamic core technology in network security. With the ever-increasing wire-speed and packets dropping and false positive the existed NIDS doesn’t fit for high-speed network any longer. Network processor can analyze packets in parallel mode and shorter inner latency by using hardware threads, multi-level memories, and obtain flexibility by using programmable components. This paper builds a validate high-speed platform for intrusion detection and achieves much good approaches, methods and ideas to overcome the speed bottleneck in current IDS.

Key words: Network processor; Intrusion detection; Multi-level parallel; Hardware thread; Scheduling policy