期刊文献+

基于高性能网络处理器的NIPS设计与实现

Design and Implementation of Network Intrusion Prevention System Based on High-Speed Network Processor
原文传递
导出
摘要 在高速网络环境下,利用入侵防御系统(IPS)对全部的网络流量进行检测是一项十分巨大挑战。网络处理器是专门处理和转发网络数据流的高速可编程处理器,在网络交换及通信设备中有着十分广泛的应用。论文首先介绍IPS的特点,及其在网络安全中的重要作用;接着,详细介绍Intel高性能网络处理器的硬件组成和框架,并给出一种基于Intel高性能网络处理器的NIPS的具体设计与实现方案。 Network Intrusion Detection and Prevention Systems are full of vitality in the fight against network intrusions. Network Intrusion Prevention System(NIPS) search for certain malicious content based on signatures and filter network traffic. Matching all traffic with these signatures is a challenge to high-speed networks. In this paper, the concept of network intrusion prevention system and its features are described. Then it introduces in detail the composition and structure of InteI High-Speed Network Processor is discussed, and analyzes the basic theory of IPS analyzed. Finally, the NIPS design and an implementation based on Intel High-Speed Network Processor is given.
出处 《信息安全与通信保密》 2009年第4期73-75,共3页 Information Security and Communications Privacy
关键词 网络处理器 入侵防御系统 微引擎 network processor intrusion prevention system micro-engine
  • 相关文献

参考文献5

  • 1CSI/FBI.Computer crime and security survey 2003[EB/OL].[2006-11-10].http://www.gocsi.com/forms/fb/csi_fbi_suvey.jhtml.
  • 2Zhang Xinyou,Li Chengzhong,Zheng Wenbin.Intrusion Prevention System Design[C].Computer and Information Technology,2004:386-390.
  • 3姬铭,江广顺.基于IXP2400的入侵防御系统设计和实现[J].微计算机信息,2007,23(27):110-112. 被引量:1
  • 4Erik J Johnson,Aaron R Kurize.IXP2400/2800 Programming[M].Intel press,2003:234-258.
  • 5Varghese G,FingerhutA J,Bonomi F.Detecting Evasion Attacks at High Speeds without Reassembly[C].Proceedings of the 2006 conference on Applications,technologies,architectures,and protocols for computer communications,2006:327-338.

二级参考文献4

  • 1胡雁,赵荣彩,陈庶民,张铮,刘霆.基于IXP1200的负载均衡设备研究与实现[J].微计算机信息,2005,21(08X):31-34. 被引量:3
  • 2Erik J.Johnson,Aaron R.Kunze. IXP2400/2800 Programming.Intel press.2003
  • 3Intel.Intel IXP2400 Network Processor Hardware Reference Manual.2003
  • 4张可,刘乃琦,陈雁.IXA架构上状态检测防火墙的一种设计框架.2004

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部