期刊文献+

高速低功耗深度报文检测方法 被引量:1

Hish speed deep packet inspection method with low power dissipation
下载PDF
导出
摘要 针对基于三态内容寻址存储器(TCAM,ternary content addressable memory)的深度报文检测(DPI,deep packet inspection)存在的高功耗问题,提出一种分级DPI方法BF-TCAM。第一级采用低功耗的并行布鲁姆过滤器(bloom fliter)排除无需检测的正常报文;第二级采用TCAM对真正需要检测的攻击报文和第一级的假阳性误判报文做进一步的检测。由于网络流量中大部分报文是正常报文,攻击报文在其中只占很少的部分,布鲁姆过滤器的假阴性(false negative)概率为0,可以保证不会产生漏检,假阳性概率很低,可以保证高速DPI检测的同时大大地降低功耗。 Hish speed deep packet inspection using TCAM faces the problem of high power dissipation.A 2-phase DPI method BF-TCAM was proposed.The first phase used parallel Bloom filters to exclude the normal packets not including attack signatures.The second phase used TCAM to inspect suspicious packets including real attack packets and false positive packets of the first phase.The Bloom filters' false negative probability is zero and false positive probability is very low.Since most of the network data traffic does not include attack signatures,the method can get high speed deep packet inspection with low power dissipation.
出处 《通信学报》 EI CSCD 北大核心 2011年第4期158-165,共8页 Journal on Communications
基金 国家高技术研究发展计划("863"计划)基金资助项目(2005AA121410)~~
关键词 深度报文检测 三态内容寻址存储器 布鲁姆过滤器 功耗 deep packet inspection TCAM Bloom filter power dissipation
  • 相关文献

参考文献14

  • 1KANG S,,SONG I,LEE Y,et al.Design and implementation of amulti-gigabit instruction and virus/worm detection system. Com-munications,2006 IEEE International Conference . 2006
  • 2LI M.An approach to reliably identifying signs of DDOS flood attacksbased on LRD traffic pattern recognition. Computers and Security . 2004
  • 3TIAN K L,,LI M.A reliable anomaly detector against low-rate DDOSattack. International Journal of Electronics and Computers . 2009
  • 4SNORT system. http://www.snort.org . 2010
  • 5Sun managed security services. http://www.sun.com/service/Managedservices/MSSequipment.pdf . 2004
  • 6JIANG W,,PRASANNA V K.Beyond TCAMs:an SRAM-basedmulti-pipeline architecture for terabit IP lookup. The 27th Confer-ence on Computer Communications,IEEE INFOCOM 2008 . 2008
  • 7DHARMAPURIKAR S.Fast and scalable pattern matching for con-tent filtering. Proceedings of the 2005 Symposium on Architecturefor Networking and Communications Systems . 2005
  • 8NETLOGIC microsystems. http://www.netlogicmicro.com/ . 2010
  • 9Weinsberg Y,Tzur-David S,Dolev D,Anker T.High performance string matching algorithm for a network intrusion prevention system(NIPS). High Performance Switching and Routing,2006 Workshop on . 2006
  • 10YU Fang,KATZ R H,LAKSHMAN T V.Gigabit rate packet pat-tern-matching using TCAM. Proc of the12th IEEE International Conference on Network Protocols . 2004

同被引文献4

引证文献1

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部