Title :
Adding Value to TCP/IP Based Information exchange Security by Specialized Hardware
Author :
Vuka!sin Pejovic;Slobodan Bojanic;Carlos Carreras
Author_Institution :
Universidad Polit?ecnica de Madrid, Ciudad Universitaria s/n, 28040, Madrid, Spain
Abstract :
Complexity of the attack space existent within the scope TCP/IP based communications makes the security problem extremely wide. Most of the transmitted data has to be processed on a daily basis by firewalls, IDSes and/or other security enforcing technologies. It is possible, however, to divide the complex security threat space and provide fast and efficient solutions to deal with some subspaces. This would reallocate the processing into specialised devices and would take some processing burden off the stated conventional technologies. A specialised hardware architecture capable of sustaining high throughput rates of up to 40 Gbps when implemented in an FPGA platform will serve as one such example. In its current development phase the hardware solution presented processes and verifies the TCP/IP specific reassembly mechanism. The misuse of the reassembly mechanism has historically led to different types of security breaches while new instances can arise unexpectedly. The presented work can be seen as a systemic solution for the monitoring of the misuse of the reassembly mechanism for preventive perspective.
Keywords :
"TCPIP","Information security","Hardware","Space technology","Data security","Intrusion detection","Monitoring","Prototypes","Humans","Robustness"
Conference_Titel :
Emerging Security Information, Systems, and Technologies, 2007. SecureWare 2007. The International Conference on
Print_ISBN :
0-7695-2989-5;978-0-7695-2989-9
Electronic_ISBN :
2162-2116
DOI :
10.1109/SECUREWARE.2007.4385325