Title :
Real-time feature extraction for high speed networks
Author :
Nguyen, David ; Memik, Gokhan ; Memik, Seda Ogrenci ; Choudhary, Alok
Author_Institution :
Dept. of Electr. & Comput. Eng., Northwestern Univ., Evanston, IL, USA
Abstract :
With the onset of Gigabit networks, current generation networking components will soon be insufficient for numerous reasons: most notably because existing methods cannot support high performance demands. Feature extraction (or flow monitoring), an essential component in anomaly detection, summarizes network behavior from a packet stream. This information is fed into intrusion detection methods such as association rule mining, outlier analysis, and classification algorithms in order to characterize network behavior. However, current feature extraction methods based on per-flow analysis are expensive, not scalable, and thus prohibitive for large-scale networks. In this paper, we propose an accurate and scalable feature extraction module (FEM) based on sketches. We present the details of the FEM design on an FPGA and show that using FPGAs we can achieve significantly better performance compared to existing software and ASIC implementations. Specifically, the optimal FEM configuration achieves 21.25 Gbps throughput and 97.61% accuracy.
Keywords :
data mining; feature extraction; field programmable gate arrays; network analysis; security of data; ASIC implementation; FPGA; Gigabit networks; anomaly detection; association rule mining; classification algorithms; feature extraction module; flow monitoring; high speed networks; intrusion detection; network behavior characterisation; outlier analysis; packet stream; real-time feature extraction; Algorithm design and analysis; Association rules; Classification algorithms; Data mining; Feature extraction; Field programmable gate arrays; High-speed networks; Information analysis; Intrusion detection; Monitoring;
Conference_Titel :
Field Programmable Logic and Applications, 2005. International Conference on
Print_ISBN :
0-7803-9362-7
DOI :
10.1109/FPL.2005.1515761