DocumentCode :
2798118
Title :
TCP reassembly for signature-based Network Intrusion Detection systems
Author :
Ngoc Thinh Tran ; Tomiyama, Shigenori ; Kittitornkun, Surin ; Vu, Tran Huy
Author_Institution :
Dept. of Comput. Eng., HCMUT, Ho Chi Minh City, Vietnam
fYear :
2012
fDate :
16-18 May 2012
Firstpage :
1
Lastpage :
4
Abstract :
Rapid development of network makes it a very important and vulnerable part of every field of life. Many intrusion detection systems are developed to protect the network using signature-based matching technique. For connection oriented protocols, such as Transmission Control Protocol, the data should be reassembled before being scanned by the matching engine. Several techniques are introduced to reassemble TCP packets on FPGA. However, they have some disadvantages such as inefficient memory, unscalable system, and unsupported complex TCP connections. In this paper, we propose a multi-linked-list approach and a combination of edge buffering scheme for TCP reassembly, which helps detecting cross packets intrusion signatures. Our architecture not only supports TCP connections with up to 4 concurrent holes, but also uses memory more efficiently than others. The experimental results show that our system can hold about 256K connections simultaneously and support up to 46K out-of-sequence connections with only 64MB DRAM.
Keywords :
DRAM chips; buffer storage; computer network security; digital signatures; field programmable gate arrays; transport protocols; DRAM; FPGA; TCP connections; TCP packet reassembly; concurrent holes; connection oriented protocols; cross packet intrusion signature detection; edge buffering scheme; matching engine; memory usage; multilinked-list approach; out-of-sequence connections; signature-based matching technique; signature-based network intrusion detection system; transmission control protocol; Buffer storage; Field programmable gate arrays; Memory management; Random access memory; Robustness; Throughput; Edge; FPGA; Linked list; Segment array; TCP reassembly;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Electrical Engineering/Electronics, Computer, Telecommunications and Information Technology (ECTI-CON), 2012 9th International Conference on
Conference_Location :
Phetchaburi
Print_ISBN :
978-1-4673-2026-9
Type :
conf
DOI :
10.1109/ECTICon.2012.6254336
Filename :
6254336
Link To Document :
بازگشت