Proceedings of 2010 Asia-Pacific Youth Conference on Communication (APYCC 2010 E-BOOK)

Kunming,China,8.7-8.8,2010

ISBN: 978-1-935068-13-6 Scientific Research Publishing, USA

E-Book 542pp Pub. Date: August 2010

Category: Computer Science & Communications

Price: $80

Title: A String Matching Based Intrusion Detection System for Gigabit Network
Source: Proceedings of 2010 Asia-Pacific Youth Conference on Communication (APYCC 2010 E-BOOK) (pp 79-82)
Author(s): Shuxia Pan, Jilin Medical College, Jilin, China
Wangjie Sun, Deptment of Science, Jilin Institute of Chemical Technology, Jilin, China
Zhigao Zheng, Deptment of Science, Jilin Institute of Chemical Technology, Jilin, China
Chang Sun, School of Software of Dalian University of Technology, Dalian, China
Abstract: In high speed network intrusion detection system, it is difficult to keep up with intrusion detection in software. Hardware based solutions are the only approach currently practical for intrusion detection on high-speed backbone networks running at around 10 Gbps. The goal of this paper is to present a finite state machine based string matching scheme for the implementation of high-speed network intrusion detection sys- tems. CAM based techniques is used for finite state machine implementation which provides a per-FSM input stream consisting of symbols representing multi-byte patterns that appear in the input data. Multiple search strings are processed in parallel using multiple FSMs. This pre-FSM classification stage is used to reduce the redundancy in the input data stream and hence allows a FSM to be implemented with relatively small re- sources that is able to operate on multiple bytes per clock cycle which can cope with an increased network throughput. Basic high-level component in the proposed scheme are described.
Free SCIRP Newsletters
Copyright © 2006-2024 Scientific Research Publishing Inc. All Rights Reserved.
Top