Network Intrusion Detection and Prevention System by Parallel Matching

碩士 === 國立中正大學 === 電機工程研究所 === 101 === The development of network is growing up quickly that accompanied by the many applications and many attacks. For the reason, it is necessary to establish the intrusion detection and prevention systems on the router or switch that can detect and prevent the netwo...

Full description

Bibliographic Details
Main Authors: Meng-Jhih Chen, 陳孟志
Other Authors: Yuan-Sun Chu
Format: Others
Language:zh-TW
Published: 2013
Online Access:http://ndltd.ncl.edu.tw/handle/17697990647085652914
Description
Summary:碩士 === 國立中正大學 === 電機工程研究所 === 101 === The development of network is growing up quickly that accompanied by the many applications and many attacks. For the reason, it is necessary to establish the intrusion detection and prevention systems on the router or switch that can detect and prevent the network intrusions in the large scale institutions. With the increase network bandwidth and the variety of the attack from Internet hacker, the request of the intrusion detection is becoming heavier. Therefore, it is a crucial topic of how to create high efficient intrusion detection and prevention. We design a system that integrate Snort rule content matching and parallelized the architecture of the content matching, focus on the speed up、high accuracy hardware processor. The frequency of our chip design can reach to 435MHz and matching for 5272 Snort rules, the speed and efficiency has significantly improved compared to the software implementation.