DocumentCode
3626465
Title
Adding Value to TCP/IP Based Information exchange Security by Specialized Hardware
Author
Vuka!sin Pejovic;Slobodan Bojanic;Carlos Carreras
Author_Institution
Universidad Polit?ecnica de Madrid, Ciudad Universitaria s/n, 28040, Madrid, Spain
fYear
2007
Firstpage
145
Lastpage
150
Abstract
Complexity of the attack space existent within the scope TCP/IP based communications makes the security problem extremely wide. Most of the transmitted data has to be processed on a daily basis by firewalls, IDSes and/or other security enforcing technologies. It is possible, however, to divide the complex security threat space and provide fast and efficient solutions to deal with some subspaces. This would reallocate the processing into specialised devices and would take some processing burden off the stated conventional technologies. A specialised hardware architecture capable of sustaining high throughput rates of up to 40 Gbps when implemented in an FPGA platform will serve as one such example. In its current development phase the hardware solution presented processes and verifies the TCP/IP specific reassembly mechanism. The misuse of the reassembly mechanism has historically led to different types of security breaches while new instances can arise unexpectedly. The presented work can be seen as a systemic solution for the monitoring of the misuse of the reassembly mechanism for preventive perspective.
Keywords
"TCPIP","Information security","Hardware","Space technology","Data security","Intrusion detection","Monitoring","Prototypes","Humans","Robustness"
Publisher
ieee
Conference_Titel
Emerging Security Information, Systems, and Technologies, 2007. SecureWare 2007. The International Conference on
ISSN
2162-2108
Print_ISBN
0-7695-2989-5;978-0-7695-2989-9
Electronic_ISBN
2162-2116
Type
conf
DOI
10.1109/SECUREWARE.2007.4385325
Filename
4385325
Link To Document