Title :
High-speed attack mitigation engine by packet filtering and rate-limiting using FPGA
Author :
Park, Sang-Kil ; Oh, Jin-Tae ; Jang, Jong-Soo
Author_Institution :
Security Gateway Syst. Team, Electron. & Telecommun. Res. Inst.
Abstract :
Recently, enterprises, service provider, and e-businesses confront increasing security and performance challenges. Securing network, host, and on-line application is absolutely important. At the same time, security function must not disturb productivity. To ensure that increasing network traffic is safe and their networks are secure, these organizations must provide security with bias toward solutions that accommodate performance demands, while providing the security and networking features required to run their businesses. That is, best solutions are those that combine high performance with topnotch security. For satisfying those requirements, we have developed hardware based and high performance security gateway system (SGS) which providing security functions such firewall, IDS, rate-limiting, and traffic metering in wire speed. In this paper, we especially describe how H/W based firewall and rate-limiting and their response coordinating engine features are implemented in SGS as a hardware chipset (FPGA)
Keywords :
Internet; field programmable gate arrays; telecommunication security; telecommunication traffic; FPGA; IDS; Internet; firewall; hardware chipset; high-speed attack mitigation engine; network traffic; packet filtering; rate-limiting; response coordinating engine features; security gateway system; traffic metering; Communication system traffic control; Computer crime; Field programmable gate arrays; Filtering; Hardware; IP networks; Productivity; Search engines; Security; Web and internet services; Attack Mitigation; Attack Response; DDoS; FPGA; Packet Filtering; Policing; Traffic Control;
Conference_Titel :
Advanced Communication Technology, 2006. ICACT 2006. The 8th International Conference
Conference_Location :
Phoenix Park
Print_ISBN :
89-5519-129-4
DOI :
10.1109/ICACT.2006.206058