DocumentCode :
2213199
Title :
Exploiting Dynamic Reconfiguration for FPGA Based Network Intrusion Detection Systems
Author :
Pontarelli, Salvatore ; Greco, Claudio ; Nobile, Enrico ; Teofili, Simone ; Bianchi, Giuseppe
Author_Institution :
Consorzio Naz. InterUniversitario per le Telecomun. (CNIT), Univ. of Rome Tor Vergata, Rome, Italy
fYear :
2010
fDate :
Aug. 31 2010-Sept. 2 2010
Firstpage :
10
Lastpage :
14
Abstract :
A Network Intrusion Detection System (NIDS) inspects the traffic flowing in a network to detect malicious content such as spam, viruses, and so on. Hardware based solutions appear necessary to face the performance requirements emerging when the goal is to deploy such systems in high speed network scenarios. However, the appropriate choice of the hardware platform is believed to be subject to at least two requirements, usually considered independent each other: i) it needs to be reprogrammable, in order to update the intrusion detection rules each time a new threat arises, and ii) it must be capable of containing the typically very large set of rules of existing NIDSs. The goal of this paper is to show that reprogrammability can be further exploited to reduce the resource requirements for the chosen platform. Specifically, we propose an FPGA-based solution that classifies and dispatches traffic to elastic buffers, connecting one buffer at a time to a dynamically reconfigurable rule matching core. This core supports only the appropriate subset of detection rules. A worst-case analysis shows that the saving in hardware resources is achieved with a relatively small buffer space, currently available in cheap, low end, FPGA boards, with no impairment on the resulting throughput.
Keywords :
computer network security; field programmable gate arrays; FPGA-based solution; NIDS; elastic buffers; network intrusion detection system; network traffic; reconfigurable rule matching core; reprogrammability; worst-case analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Field Programmable Logic and Applications (FPL), 2010 International Conference on
Conference_Location :
Milano
ISSN :
1946-1488
Print_ISBN :
978-1-4244-7842-2
Type :
conf
DOI :
10.1109/FPL.2010.13
Filename :
5694212
Link To Document :
بازگشت