A Fast and Configurable Pattern Matching Hardware Architecture for Intrusion Detection

Yizhen Liu,Daxiong Xu,Dong Liu,Lingge Sun
DOI: https://doi.org/10.1109/WKDD.2009.111
2009-01-01
Abstract:The current hardware architectures of intrusion detection system have several limitations on performance and configurability. In this paper we describe the architecture design and hardware implementation of gigabits NIDS using a programmable network processor and a FPGA co-processor. We discuss the requirements of NIDS, system hardware architecture and report measurements. In particular, we demonstrate performance improved by optimized parallel pattern match processing and efficient memory access in field programmable gate array (FPGA). We show an NIDS which can exploit our approach hardware platform, and make suggestions about implementation features that can significantly improve the performance and configurability of intrusion detection systems.
What problem does this paper attempt to address?