2010 Asia-Pacific Conference on Information Theory (APCIT 2010 E-BOOK)

Xi'an,China,10.1-10.2,2010

ISBN: 978-1-935068-47-1 Scientific Research Publishing, USA

E-Book 506pp Pub. Date: November 2010

Category: Computer Science & Communications

Price: $80

Title: Design of Hardware-Based High-Speed Intrusion Detection System for Telecommunications Network
Source: 2010 Asia-Pacific Conference on Information Theory (APCIT 2010 E-BOOK) (pp 178-183)
Author(s): Peng Huang, Institute of Electronic Technology, Information Engineering University of PLA, Zhengzhou, Henan 450004, China
Yuanbo Guo, Institute of Electronic Technology, Information Engineering University of PLA, Zhengzhou, Henan 450004, China
Wei Liu, Institute of Electronic Technology, Information Engineering University of PLA, Zhengzhou, Henan 450004, China
Abstract: In recent years, hacker attacks cause great damage to the telecommunications network as well as the whole society. Intrusion detection system (IDS) for telecommunications network are needed ur- gently. However, the current software-based IDS often fail to keep up with high-speed telecommunica- tion network links. This paper designs a hardware-based NIDS, deploys it between the border routers and the user subnets to complete of the safety testing of high-speed telecommunications network. Net- work data streams are pre-filtered by a white list and a black list implemented with TCAM firstly. Fil- tered packets are then distributed to multiple detection engines where packet headers are classified by decision tree algorithm. Packet payloads concatenated with serial number of packet header after classi- fication are checked by Bloom Filter and malicious ones are sent to Bit-Split AC automaton for exact match to eliminate false positives. Experimental results show that the system is able to achieve detection rate of 10Gbps with very low resource consumption.
Free SCIRP Newsletters
Copyright © 2006-2024 Scientific Research Publishing Inc. All Rights Reserved.
Top