计算机与现代化 ›› 2012, Vol. 1 ›› Issue (1): 170-172.doi: 10.3969/j.issn.1006-2475.2012.01.044

• 信息安全 • 上一篇    下一篇

基于FPGA的Gigabit入侵检测系统设计与实现

李志祥,林克成,王寅龙,王希武,李前进   

  1. 军械工程学院计算机工程系,河北 石家庄 050003
  • 收稿日期:2011-10-18 修回日期:1900-01-01 出版日期:2012-01-10 发布日期:2012-01-10

Design and Implementation of Gigabit NIDS Based on FPGA

LI Zhi-xiang, LIN Ke-cheng, WANG Yin-long, WANG Xi-wu, LI Qian-jin   

  1. Department of Computer Engineering, Ordnance Engineering College, Shijiazhuang 050003, China
  • Received:2011-10-18 Revised:1900-01-01 Online:2012-01-10 Published:2012-01-10

摘要: 随着网络带宽的增长,基于软件的入侵检测系统已不能适应千兆网络安全的需求。本文基于FPGA实现了千兆网入侵检测系统,其中的流量捕获、数据包解析、规则集模式匹配等计算密集的任务模块由FPGA中的高速运算逻辑实现,而人机交互部分由嵌入式系统实现。测试结果显示,系统在1Gbps最小包压力流量下进行数据包分析与检测时,可以达到0丢包率。

关键词: 入侵检测系统, 千兆网络, FPGA

Abstract: Traditional software-based network intrusion detection systems (NIDS) are becoming strained as network data-rate increases. A gigabit NIDS is implemented based on FPGA. The computationally intensive components of a NIDS such as stream capturing, packet resolving and pattern matching of rule set are implemented based on high-speed logic cells of FPGA. While human-machine interfacing module is implemented based on embedded system. Test shows that when working in pressing gigabit network, the system can achieve zero-loss rate.

Key words: NIDS, gigabit network, FPGA

中图分类号: