Abstract
To achieve fast packet processing and dynamic adaptation of intrusion patterns that are continuously added, a new high performance network intrusion detection system using Intel’s network processor, IXP1200, is proposed. Unlike traditional intrusion detection engines, which has been implemented by either software or hardware so far, we propose an optimized architecture and algorithms, exploiting the features of network processor. Through implementation and performance evaluation, we show the proprieties of the proposed approach.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
Sidhu, R., Prasanna, V.K.: Fast Regular Expression Matching using FPGAs. In: IEEE Symposium on Field-Programmable Custom Computing Machines (FCCM 2001) (2001)
Hutchings, B.L., Franklin, R., Carver, D.: Assisting Network Intrusion Detection with Reconfigurable Hardware. In: IEEE Symposium on Field-Programmable Custom Computing Machines (FCCM 2002) (2002)
Cho, Y.H., Navab, S., Mangione-Smith, W.H.: Specialized Hardware for Deep Network Packet Filtering. In: Glesner, M., Zipf, P., Renovell, M. (eds.) FPL 2002. LNCS, vol. 2438, pp. 452–461. Springer, Heidelberg (2002)
Mukherjee, B., Heberlein, L.T., Levitt, K.N.: Network Intrusion Detection. IEEE Network 8(3), 26–41 (1994)
Snort homepage, available at http://www.snort.org
Roesch, M., Green, C.: Snort User Manual, Verson 1.8.6/2.0.0 (2002/2003)
Desai, N.: Increasing Performance in High Speed NIDS, A look at Snort’s Internals (2002)
Intel corporation, Intel IXP1200/2400 Network Processor Family Hardware Reference Manual (2001/2003)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2004 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Cho, H., Kim, D., Kim, J., Doh, Y., Jang, J. (2004). Network Processor Based Network Intrusion Detection System. In: Kahng, HK., Goto, S. (eds) Information Networking. Networking Technologies for Broadband and Mobile Networks. ICOIN 2004. Lecture Notes in Computer Science, vol 3090. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-25978-7_98
Download citation
DOI: https://doi.org/10.1007/978-3-540-25978-7_98
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-540-23034-2
Online ISBN: 978-3-540-25978-7
eBook Packages: Springer Book Archive