DocumentCode :
1841315
Title :
Hardware implementations of high-speed network monitors
Author :
Tanba, Hiroaki ; Yamada, Yasuhiro ; Kitamichi, Junji ; Kurda, Kenichi
Author_Institution :
Graduate Sch. of Comput. Sci. & Eng., Aizu Univ., Aizu-Wakamatsu, Japan
fYear :
2005
fDate :
27-29 April 2005
Firstpage :
33
Lastpage :
36
Abstract :
Recently, many kinds of malicious attacks on the Internet such as denial of service (DoS) attacks are increasing, and many unnecessary packets waste network resources. Network monitors to watch and filtering these unnecessary packets have been proposed. However, in the present network monitors implemented using several servers and monitoring software, it will be difficult to watch in real time and remove unnecessary packets at the very high-speed backbone network such as intercontinental one. One of the methods to realize a real time network monitor is an implementation by the hardware. Therefore, in this research, we propose a hardware architecture that detects IP flooding and SYN flood; these are kinds of DoS attacks. We design the hardware circuits in ASIC and FPGA. As the results of logic synthesis, we confirm that these detection circuits can work on the high-speed traffic such as more than 10 millions packets/sec.
Keywords :
Internet; application specific integrated circuits; computer networks; field programmable gate arrays; high-speed techniques; integrated circuit design; logic design; monitoring; telecommunication security; telecommunication traffic; ASIC; FPGA; IP flooding detection; Internet; SYN flooding detection; application specific integrated circuits; denial of service attacks; detection circuits; field programmable gate arrays; hardware architecture; hardware circuits; high-speed network monitors; high-speed traffic; logic synthesis; real time network monitor; telecommunication security; telecommunication traffic; Circuits; Computer crime; Floods; Hardware; High-speed networks; IP networks; Information filtering; Information filters; Watches; Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
VLSI Design, Automation and Test, 2005. (VLSI-TSA-DAT). 2005 IEEE VLSI-TSA International Symposium on
Print_ISBN :
0-7803-9060-1
Type :
conf
DOI :
10.1109/VDAT.2005.1500013
Filename :
1500013
Link To Document :
بازگشت