Author Login Chief Editor Login Reviewer Login Editor Login Remote Office

Computer Engineering ›› 2006, Vol. 32 ›› Issue (7): 160-162.

• Security Technology • Previous Articles     Next Articles

Intrusion Detection Methods Based on Network Processor

WEI Lihua1,2, ZHANG Xiaoming2, TANG Yuhua2, SUN Zhigang2   

  1. 1. School of Information Engineering, Jiaxing University in Zhejiang Province, Jiaxing 314001;2. School of Computer, National University of Defence Technology, Changsha 410073
  • Online:2006-04-05 Published:2006-04-05

基于网络处理器的入侵检测方法

魏利华 1,2,张晓明2,唐玉华2,孙志刚2   

  1. 1. 浙江嘉兴学院信息工程学院,嘉兴 314001;2. 国防科技大学计算机学院,长沙 410073

Abstract: Intrusion detection is a dynamic core technology in network security. With the ever-increasing wire-speed and packets dropping and false positive the existed NIDS doesn’t fit for high-speed network any longer. Network processor can analyze packets in parallel mode and shorter inner latency by using hardware threads, multi-level memories, and obtain flexibility by using programmable components. This paper builds a validate high-speed platform for intrusion detection and achieves much good approaches, methods and ideas to overcome the speed bottleneck in current IDS.

Key words: Network processor; Intrusion detection; Multi-level parallel; Hardware thread; Scheduling policy

摘要: 入侵检测是网络安全的核心技术。随着网络速度的不断提升,现有NIDS 的检测速度已不适应千兆位以上网络,漏检率和误检率越来越高。网络处理器以高度并行、硬件多线程、多级存储和灵活可编程等先进技术提供高速的数据包处理性能。该文对利用网络处理器解决入侵检测的速度瓶颈提出了观点、方法和策略,设计和实现了一个面向入侵检测的高速网络处理器原型。

关键词: 网络处理器;入侵检测;多级并行;硬件线程;调度策略