شماره ركورد كنفرانس :
4093
عنوان مقاله :
Enhancing search speed in preprocessing mechanism of network intrusion detection systems using network on chip
پديدآورندگان :
Najjar-Ghabel Samad s.najjar@tabrizu.ac.ir Department of Electrical and Computer Engineering University of Tabriz , Mohammad Khanli Leyli l-khanli@tabrizu.ac.ir University of Tabriz
كليدواژه :
field , programmable gate array (FPGA) , Heracles , Intrusion detection systems (IDS) , Network Security , Network on Chip (NoC) , Snort
عنوان كنفرانس :
سومين كنفرانس ملي محاسبات توزيعي و پردازش داده هاي بزرگ
چكيده فارسي :
Security of computer networks is a crucial part of today’s world. There are many existing tools that provide security for computer networks. Intrusion detection system (IDS) is one of these security tools that protects its local network from attacks by detection any malicious network activity. Every kind of IDS has some limitations about detection rate or execution time. Signature-based IDS is widely used in a computer network. A signature-based IDS has CPU limitations in the real-world networks. In this paper, a hardware approach was applied to the previous work. In fact, using network on chip (NoC) in the preprocessing part of IDSs is proposed. The results of implementation prove that NoC can reduce the execution time compared to that of the previous work. Therefore, this approach can increase the performance of all local networks while false alarm rate remained in an acceptable rate. Furthermore, increasing the speed of IDSs provides more security for the local network by increasing the security of IDSs
چكيده لاتين :
Security of computer networks is a crucial part of today’s world. There are many existing tools that provide security for computer networks. Intrusion detection system (IDS) is one of these security tools that protects its local network from attacks by detection any malicious network activity. Every kind of IDS has some limitations about detection rate or execution time. Signature-based IDS is widely used in a computer network. A signature-based IDS has CPU limitations in the real-world networks. In this paper, a hardware approach was applied to the previous work. In fact, using network on chip (NoC) in the preprocessing part of IDSs is proposed. The results of implementation prove that NoC can reduce the execution time compared to that of the previous work. Therefore, this approach can increase the performance of all local networks while false alarm rate remained in an acceptable rate. Furthermore, increasing the speed of IDSs provides more security for the local network by increasing the security of IDSs