Summary: | 碩士 === 國立中正大學 === 電機工程研究所 === 101 === The development of network is growing up quickly that accompanied by the many applications and many attacks. For the reason, it is necessary to establish the intrusion detection and prevention systems on the router or switch that can detect and prevent the network intrusions in the large scale institutions. With the increase network bandwidth and the variety of the attack from Internet hacker, the request of the intrusion detection is becoming heavier. Therefore, it is a crucial topic of how to create high efficient intrusion detection and prevention. We design a system that integrate Snort rule content matching and parallelized the architecture of the content matching, focus on the speed up、high accuracy hardware processor. The frequency of our chip design can reach to 435MHz and matching for 5272 Snort rules, the speed and efficiency has significantly improved compared to the software implementation.
|