首页> 外文会议>International Conference on Advanced Information Networking and Applications >The Cost Effective Pre-processing Based NFA Pattern Matching Architecture for NIDS
【24h】

The Cost Effective Pre-processing Based NFA Pattern Matching Architecture for NIDS

机译:基于成本有效的NFA模式匹配架构的NFA模式

获取原文

摘要

Network Intrusion Detection System (NIDS) is a system which can detect network attacks resulted from worms and viruses on the Internet. An efficient pattern matching algorithm plays an important role in NIDS. There have been many proposed methods for pattern matching algorithms. Traditionally, the multi-character NFA that is capable of matching multiple characters per cycle can be built by duplicating entire circuit of 1-character architecture. In this paper, we propose a pre-processing based architecture to improve the original multi-character architecture. The design of the proposed architecture and its implementation in FPGA are described in details. Our simulation results show that the proposed architecture performs better than all the existing Brute-Force based approaches in terms of the throughput and the slice utilization. Specifically, the proposed architectures of 2-character and 4-character designs can achieve the throughputs of 4.68 and 7.27 Gbps and the slice utilization of 2.86 and 2.10 in terms of char/slice, respectively.
机译:网络入侵检测系统(NIDS)是一个系统,可以检测因互联网上的蠕虫和病毒引起的网络攻击。一个有效的模式匹配算法在NID中起着重要作用。有许多关于模式匹配算法的方法。传统上,可以通过复制1个字符架构的整个电路来构建能够匹配多个字符的多字符NFA。在本文中,我们提出了一种基于预处理的架构来改善原始的多字符架构。详细描述了所提出的体系结构及其在FPGA中的实现。我们的仿真结果表明,该架构在吞吐量和切片利用方面表现优于所有现有的布鲁斯力的方法。具体而言,2个字符和4个字符设计的拟议架构可以分别达到4.68和7.27 Gbps的吞吐量,分别在Char / Slice方面的2.86和2.10的切片利用率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号