DocumentCode :
459445
Title :
Design and Implementation of a Multi-gigabit Intrusion and Virus/Worm Detection System
Author :
Kang, Seok-Min ; Song, Il-Seop ; Lee, Youngseok ; Kwon, Taeck-Geun
Author_Institution :
Dept. of Computer Science & Engineering, Chungnam National University, Daejeon, Korea. esemkang@cnu.ac.kr
Volume :
5
fYear :
2006
fDate :
38869
Firstpage :
2136
Lastpage :
2141
Abstract :
In order to support a line-speed intrusion detection, a hardware-based solution for an intrusion detection is required, because the traditional Intrusion Detection System (IDS) based on software does not provide enough performance. In this paper, we have proposed a network processor based intrusion detection system supporting up to a 10 Gbps interfaces with deep packet inspection. To achieve higher performance, we have employed a Ternary Content Addressable Memory (TCAM) and invented a parallel TCAM accessing scheme with storing all position-aware sub-patterns in TCAM. In addition, the parallel TCAM access is applicable to the multi-packet inspection and plenty of very large patterns such as virus and worm signatures. With various experimental results, we have clearly justified the proposed algorithm works well for a multi-gigabit intrusion and virus/worm detection system.
Keywords :
Associative memory; Computer science; Computer worms; Design engineering; IP networks; Inspection; Intrusion detection; Pattern matching; Search engines; Software performance; intrusion detection system; network processor; network security; pattern matching;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, 2006. ICC '06. IEEE International Conference on
Conference_Location :
Istanbul
ISSN :
8164-9547
Print_ISBN :
1-4244-0355-3
Electronic_ISBN :
8164-9547
Type :
conf
DOI :
10.1109/ICC.2006.255086
Filename :
4024481
Link To Document :
بازگشت