• DocumentCode
    3413807
  • Title

    A Hardware-based Architecture to Support Flexible Real-Time Parallel Intrusion Detection

  • Author

    Mott, Stephen ; Hart, Samuel ; Montminy, David ; Williams, Paul ; Baldwin, Rusty

  • Author_Institution
    Air Force Inst. of Technol., Wright Patterson AFB
  • fYear
    2007
  • fDate
    16-18 April 2007
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    Providing security in today´s complex computing systems is a daunting task. As systems (of systems) grow both increasingly pervasive and complex, defending them from attack or mischance at the systems of systems level becomes ever more challenging. We propose moving some security monitoring tasks from software to hardware which will allow real time detection of intrusions and errors. Our flexible architecture uses re configurable logic (such as field programmable gate arrays (FPGAs)) and operates in parallel with a general purpose computing environment. To that end, new hardware primitives are proposed that allow for gathering and monitoring the state of the main processor transparently (that is, the main processor is unaware of the monitoring) in real time. The result is a decrease in workload for the main processor while enhancing security. The monitoring primitives are tightly coupled with the monitored software, and can readily and automatically respond to changes in system characteristics such as new software applications or devices. By focusing on specific system components, including their interface with other system components, we believe we can enhance system of system security in ways not readily achievable using conventional, system-wide monitoring techniques.
  • Keywords
    field programmable gate arrays; security of data; system monitoring; systems analysis; field programmable gate arrays; flexible real-time parallel intrusion detection; hardware-based architecture; security monitoring tasks; system security; system-wide monitoring; systems of systems level; Computer architecture; Computerized monitoring; Concurrent computing; Field programmable gate arrays; Hardware; Intrusion detection; Operating systems; Programmable logic arrays; Real time systems; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    System of Systems Engineering, 2007. SoSE '07. IEEE International Conference on
  • Conference_Location
    San Antonio, TX
  • Print_ISBN
    1-4244-1159-9
  • Electronic_ISBN
    1-4244-1160-2
  • Type

    conf

  • DOI
    10.1109/SYSOSE.2007.4304258
  • Filename
    4304258