A FPGA-based deep packet inspection engine for network intrusion detection system

dc.contributor.authorThinh, Tran Ngoc
dc.contributor.authorHieu, Tran Trung
dc.contributor.authorDung, Van Quoc
dc.contributor.authorKittitornkun, Surin
dc.date.accessioned2026-08-06T10:04:48Z
dc.date.available2026-08-06T10:04:48Z
dc.date.issued2012-10-02
dc.description.abstractPattern matching has became a bottleneck of software based Network Intrusion Detection System (NIDS) as the number of signature have recently increased dramatically. Many FPGA-based architectures for detecting malicious patterns have been proposed recently. However, these approaches have just considered matching pattern separately while more and more complex combination of several patterns are utilized to describe intrusion activities. In this paper we present our work which concentrates on multi-pattern signature and propose a FPGA-based deep packet inspection engine for NIDS. The system can support both static and dynamic patterns. We employ Snort signature set and realize our system on NetFPGA platform. The evaluation on real network environment shows that our system can maintain gigabit line rate throughput without dropping packets. © 2012 IEEE.
dc.identifier.citation2012 9th International Conference on Electrical Engineering Electronics Computer Telecommunications and Information Technology Ecti Con 2012, 2012
dc.identifier.doi10.1109/ECTICon.2012.6254301
dc.identifier.other2-s2.0-84866764725
dc.identifier.urihttps://dspace.kmitl.ac.th/handle/123456789/4351
dc.source2012 9th International Conference on Electrical Engineering Electronics Computer Telecommunications and Information Technology Ecti Con 2012
dc.subjectcuckoo hashing
dc.subjectDPI
dc.subjectFPGA
dc.subjectmulti-pattern matching
dc.subjectNFA
dc.subjectNIDS/NIPS
dc.subjectRegular Expression
dc.titleA FPGA-based deep packet inspection engine for network intrusion detection system
dc.typeConference Paper

Files

Collections