Research on range matching for wire-speed hardware NIDS
|更新时间:2024-10-14
|
Research on range matching for wire-speed hardware NIDS
Issue 10, Pages: 7-12(2006)
作者机构:
1. 国防科学技术大学计算机学院
2. 国防科学技术大学计算机学院,湖南,长沙,410073
作者简介:
基金信息:
DOI:
CLC:TP393.08
Published:2006
稿件说明:
移动端阅览
CHEN Shu-hui, SUN Zhi-gang, SU Jin-shu. Research on range matching for wire-speed hardware NIDS[J]. 2006, (10): 7-12.
DOI:
CHEN Shu-hui, SUN Zhi-gang, SU Jin-shu. Research on range matching for wire-speed hardware NIDS[J]. 2006, (10): 7-12.DOI:
Research on range matching for wire-speed hardware NIDS
摘要
为解决硬件入侵检测系统的规则匹配问题
提出了一种降低存储资源的范围匹配算法LRC-RM
将规则中的端口范围映射成压缩位向量
并将位向量组织成扩展平衡二叉树
然后对实现的系统进行了评估。采用该技术的网络入侵检测系统
使用的存储空间只有已有算法的1%
有利于硬件在片内完成查找过程
可实现端口范围在OC192链路的线速匹配。
Abstract
To solve the rule matching problem of hardware NIDS
a range matching algorithm LRC-RM was proposed
with more efficient memory utilization.The approach mapped the port range into a compressed bit vector and organized the bit vectors as an extended balanced binary tree.Experiments were employed to show that NIDS using this approach can perform wire-speed range matching for OC-192 links
while saving 99% memory resource comparing to the existing methods.The algorithm is easy to be implemented within a chip without additional RAM.