NIDS(Network Intrusion Detection Systems)plays a vital role in security threats to computers and networks.With the onset of gigabit networks,hardware-based Intrusion Detection System gains popularity because of its hi...NIDS(Network Intrusion Detection Systems)plays a vital role in security threats to computers and networks.With the onset of gigabit networks,hardware-based Intrusion Detection System gains popularity because of its high performance when compared to the software-based NIDS.The software-based system limits parallel execution,which in turn confines the performance of a modern network.This paper presents a signature-based lookup technique using reconfigurable hardware.Content Addressable Memory(CAM)is used as a lookup table architecture to improve the speed instead of search algorithms.To minimize the power and to increase the speed,pre-computation based CAM(PBCAM)can be used,as this technique avoids repeated search comparisons.PBCAM employs the two-stage comparison with a parameter memory in the first stage and data memory in the second stage.Only the matched data in the parameter memory are compared in the data memory.This reduces the number of comparisons,thereby increasing the speed of the system.In this work dual-port RAM-based PBCAM(DP-PBCAM)is used to design a signature-based intrusion detection system.A low power parameter extractor is used with a minimum number of gates for precomputation.The hardware implementation is done using Xilinx Spartan 3E FPGA.The proposed DP-PBCAM lookups support a gigabit-speed of 7.42 Gbps.展开更多
Information and communication technologies are spreading rapidly due to their fast proliferation in many fields.The number of Internet users has led to a spike in cyber-attack incidents.E-commerce applications,such as...Information and communication technologies are spreading rapidly due to their fast proliferation in many fields.The number of Internet users has led to a spike in cyber-attack incidents.E-commerce applications,such as online banking,marketing,trading,and other online businesses,play an integral role in our lives.Network Intrusion Detection System(NIDS)is essential to protect the network from unauthorized access and against other cyber-attacks.The existing NIDS systems are based on the Backward Oracle Matching(BOM)algorithm,which minimizes the false alarm rate and causes of high packet drop ratio.This paper discussed the existing NIDS systems and different used pattern-matching techniques regarding their weaknesses and limitations.To address the existing system issues,this paper proposes an enhanced version of the BOM algorithm by using multiple pattern-matching methods for the NIDS system to improve the network performance.The proposed solution is tested in simulation with existing solutions using the Snort and NSL-KDD datasets.The experimental results indicated that the proposed solution performed better than the existing solutions and achieved a 5.17%detection rate and a 0.22%lower false alarm rate than the existing solution.展开更多
文摘NIDS(Network Intrusion Detection Systems)plays a vital role in security threats to computers and networks.With the onset of gigabit networks,hardware-based Intrusion Detection System gains popularity because of its high performance when compared to the software-based NIDS.The software-based system limits parallel execution,which in turn confines the performance of a modern network.This paper presents a signature-based lookup technique using reconfigurable hardware.Content Addressable Memory(CAM)is used as a lookup table architecture to improve the speed instead of search algorithms.To minimize the power and to increase the speed,pre-computation based CAM(PBCAM)can be used,as this technique avoids repeated search comparisons.PBCAM employs the two-stage comparison with a parameter memory in the first stage and data memory in the second stage.Only the matched data in the parameter memory are compared in the data memory.This reduces the number of comparisons,thereby increasing the speed of the system.In this work dual-port RAM-based PBCAM(DP-PBCAM)is used to design a signature-based intrusion detection system.A low power parameter extractor is used with a minimum number of gates for precomputation.The hardware implementation is done using Xilinx Spartan 3E FPGA.The proposed DP-PBCAM lookups support a gigabit-speed of 7.42 Gbps.
文摘Information and communication technologies are spreading rapidly due to their fast proliferation in many fields.The number of Internet users has led to a spike in cyber-attack incidents.E-commerce applications,such as online banking,marketing,trading,and other online businesses,play an integral role in our lives.Network Intrusion Detection System(NIDS)is essential to protect the network from unauthorized access and against other cyber-attacks.The existing NIDS systems are based on the Backward Oracle Matching(BOM)algorithm,which minimizes the false alarm rate and causes of high packet drop ratio.This paper discussed the existing NIDS systems and different used pattern-matching techniques regarding their weaknesses and limitations.To address the existing system issues,this paper proposes an enhanced version of the BOM algorithm by using multiple pattern-matching methods for the NIDS system to improve the network performance.The proposed solution is tested in simulation with existing solutions using the Snort and NSL-KDD datasets.The experimental results indicated that the proposed solution performed better than the existing solutions and achieved a 5.17%detection rate and a 0.22%lower false alarm rate than the existing solution.