Title :
A Hardware-based Architecture to Support Flexible Real-Time Parallel Intrusion Detection
Author :
Mott, Stephen ; Hart, Samuel ; Montminy, David ; Williams, Paul ; Baldwin, Rusty
Author_Institution :
Air Force Inst. of Technol., Wright Patterson AFB
Abstract :
Providing security in today´s complex computing systems is a daunting task. As systems (of systems) grow both increasingly pervasive and complex, defending them from attack or mischance at the systems of systems level becomes ever more challenging. We propose moving some security monitoring tasks from software to hardware which will allow real time detection of intrusions and errors. Our flexible architecture uses re configurable logic (such as field programmable gate arrays (FPGAs)) and operates in parallel with a general purpose computing environment. To that end, new hardware primitives are proposed that allow for gathering and monitoring the state of the main processor transparently (that is, the main processor is unaware of the monitoring) in real time. The result is a decrease in workload for the main processor while enhancing security. The monitoring primitives are tightly coupled with the monitored software, and can readily and automatically respond to changes in system characteristics such as new software applications or devices. By focusing on specific system components, including their interface with other system components, we believe we can enhance system of system security in ways not readily achievable using conventional, system-wide monitoring techniques.
Keywords :
field programmable gate arrays; security of data; system monitoring; systems analysis; field programmable gate arrays; flexible real-time parallel intrusion detection; hardware-based architecture; security monitoring tasks; system security; system-wide monitoring; systems of systems level; Computer architecture; Computerized monitoring; Concurrent computing; Field programmable gate arrays; Hardware; Intrusion detection; Operating systems; Programmable logic arrays; Real time systems; Security;
Conference_Titel :
System of Systems Engineering, 2007. SoSE '07. IEEE International Conference on
Conference_Location :
San Antonio, TX
Print_ISBN :
1-4244-1159-9
Electronic_ISBN :
1-4244-1160-2
DOI :
10.1109/SYSOSE.2007.4304258