KMITL
Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1
Browse
6 results
Search Results
- Some of the metrics are blocked by yourconsent settings
Item type:Item, TCP reassembly for signature-based network intrusion detection systems(2012-10-02) ;Thinh, Tran Ngoc ;Tomiyama, Shigenori ;Kittitornkun, SurinVu, Tran HuyRapid development of network makes it a very important and vulnerable part of every field of life. Many intrusion detection systems are developed to protect the network using signature-based matching technique. For connection oriented protocols, such as Transmission Control Protocol, the data should be reassembled before being scanned by the matching engine. Several techniques are introduced to reassemble TCP packets on FPGA. However, they have some disadvantages such as inefficient memory, unscalable system, and unsupported complex TCP connections. In this paper, we propose a multi-linked-list approach and a combination of edge buffering scheme for TCP reassembly, which helps detecting cross packets intrusion signatures. Our architecture not only supports TCP connections with up to 4 concurrent holes, but also uses memory more efficiently than others. The experimental results show that our system can hold about 256K connections simultaneously and support up to 46K out-of-sequence connections with only 64MB DRAM. © 2012 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Item, A FPGA-based deep packet inspection engine for network intrusion detection system(2012-10-02) ;Thinh, Tran Ngoc ;Hieu, Tran Trung ;Dung, Van QuocKittitornkun, SurinPattern matching has became a bottleneck of software based Network Intrusion Detection System (NIDS) as the number of signature have recently increased dramatically. Many FPGA-based architectures for detecting malicious patterns have been proposed recently. However, these approaches have just considered matching pattern separately while more and more complex combination of several patterns are utilized to describe intrusion activities. In this paper we present our work which concentrates on multi-pattern signature and propose a FPGA-based deep packet inspection engine for NIDS. The system can support both static and dynamic patterns. We employ Snort signature set and realize our system on NetFPGA platform. The evaluation on real network environment shows that our system can maintain gigabit line rate throughput without dropping packets. © 2012 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Item, Massively parallel cuckoo pattern matching applied for NIDS/NIPS(2010-05-21) ;Thinh, Tran NgocKittitornkun, SurinThis paper describes a Cuckoo-based Pattern Matching (CPM) engine based on a recently developed hashing algorithm called Cuckoo Hashing. We implement the improved parallel Cuckoo Hashing suitable for hardware-based multi-pattern matching with arbitrary length. CPM can rapidly update the static pattern set without reconfiguration while consuming the lowest amount of hardware. With the power of massively parallel processing, the speedup of CPM is up to 128X as compared with serial Cuckoo implementation. Compared to other hardware systems, CPM is far better in performance and saves 30% of the area. © 2010 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Item, PAMELA: Pattern matching engine with Limited-time updAte for NIDS/NIPS(2009-01-01) ;Thinh, Tran Ngoc ;Kittitornkun, SurinTomiyama, ShigenoriSeveral hardware-based pattern matching engines for network intrusion/prevention detection systems (NIDS/NIPSs) can achieve high throughput with less hardware resources. However, their flexibility to update new patterns is limited and still challenging. This paper describes a PAttern Matching Engine with Limited-time updAte (PAMELA) engine using a recently proposed hashing algorithm called Cuckoo Hashing. PAMELA features on-the-fly pattern updates without reconfiguration, more efficient hardware utilization, and higher performance compared with other works. First, we implement the improved parallel exact pattern matching with arbitrary length based on Cuckoo Hashing and linkedlist technique. Second, while PAMELA is being updated with new attack patterns, both stack and FIFO are utilized to bound insertion time due to the drawback of Cuckoo Hashing and to avoid interruption of input data stream. Third, we extend the system for multi-character processing to achieve higher throughput. Our engine can accommodate the latest Snort rule-set, an open source NIDS/NIPS, and achieve the throughput up to 8.8 Gigabit per second while consuming the lowest amount of hardware. Compared to other approaches, ours is far more efficient than any other implemented on Xilinx FPGA architectures. Copyright © 2009 The Institute of Electronics, Information and Communication Engineers. - Some of the metrics are blocked by yourconsent settings
Item type:Item, Applying Cuckoo Hashing for FPGA-based pattern matching in NIDS/NIPS(2007-12-01) ;Thinh, Tran Ngoc ;Kittitornkun, SurinTomiyama, ShigenoriPattern matching for network intrusion/prevention detection requires extremely high throughput with frequent updates to support new attack patterns. Most of current hardware implementations have outstanding performance over software implementations. However, the requirement for dynamic update pattern set is still challenging for hardware researchers. This paper describes a novel FPGA-based pattern matching architecture using a recent hashing algorithm called Cuckoo Hashing. The proposed architecture features on-the-fly pattern updates without reconfiguration, more efficient hardware utilization, and higher performance. Through various algorithmic changes of Cuckoo Hashing, we can implement parallel pattern matching on SRAM-based FPGA. Our system can accommodate the latest Snort rule-set, an open source Network Intrusion Detection/Prevention System, and achieve the highest utilization in terms of SRAM per character and Logic Cells per character at 17 bits/character and 0.043 Logic Cells/character, respectively on major Xilinx Virtex architectures. Compared to others, ours is much more efficient than any other Xilinx FPGA architectures. © 2007 IEEE. - Some of the metrics are blocked by yourconsent settings
Item type:Item, Systolic array for string matching in NIDS(2007-12-01) ;Thinh, Tran NgocKittitornkun, SurinIn this paper, the rule set of a Network Intrusion Detection System, SNORT [1], is deeply analyzed and a compact encoding method to reduce the memory space for storing the payload content strings of entire rules is proposed. This method can approximately reduce up to 50% of area cost when compared with traditional ASCII coding method. After that, we implement a reconfigurable hardware sub-system for Snort payload matching using systolic design technique. Our system is a processor array architecture that can match strings with throughput up to 3.86 Gbps and area efficient manner.
