• DocumentCode
    459445
  • Title

    Design and Implementation of a Multi-gigabit Intrusion and Virus/Worm Detection System

  • Author

    Kang, Seok-Min ; Song, Il-Seop ; Lee, Youngseok ; Kwon, Taeck-Geun

  • Author_Institution
    Dept. of Computer Science & Engineering, Chungnam National University, Daejeon, Korea. esemkang@cnu.ac.kr
  • Volume
    5
  • fYear
    2006
  • fDate
    38869
  • Firstpage
    2136
  • Lastpage
    2141
  • Abstract
    In order to support a line-speed intrusion detection, a hardware-based solution for an intrusion detection is required, because the traditional Intrusion Detection System (IDS) based on software does not provide enough performance. In this paper, we have proposed a network processor based intrusion detection system supporting up to a 10 Gbps interfaces with deep packet inspection. To achieve higher performance, we have employed a Ternary Content Addressable Memory (TCAM) and invented a parallel TCAM accessing scheme with storing all position-aware sub-patterns in TCAM. In addition, the parallel TCAM access is applicable to the multi-packet inspection and plenty of very large patterns such as virus and worm signatures. With various experimental results, we have clearly justified the proposed algorithm works well for a multi-gigabit intrusion and virus/worm detection system.
  • Keywords
    Associative memory; Computer science; Computer worms; Design engineering; IP networks; Inspection; Intrusion detection; Pattern matching; Search engines; Software performance; intrusion detection system; network processor; network security; pattern matching;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2006. ICC '06. IEEE International Conference on
  • Conference_Location
    Istanbul
  • ISSN
    8164-9547
  • Print_ISBN
    1-4244-0355-3
  • Electronic_ISBN
    8164-9547
  • Type

    conf

  • DOI
    10.1109/ICC.2006.255086
  • Filename
    4024481