loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
13th Annual IEEE Symposium on Field-Programmable Custom Computing Machines (FCCM'05)
Fast Reconfiguring Deep Packet Filter for 1+ Gigabit Network
Los Alamitos
April 18-April 20
ISBN: 0-7695-2445-1
Young H. Cho, University of California at Los Angeles
William H. Mangione-Smith, University of California at Los Angeles
Due to increasing number of network worms and virus, many computer network users are vulnerable to attacks. Unless network security systems use more advanced methods of content filtering such as deep packet inspection, the problem will get worse. However, searching for patterns at multiple offsets in entire content of network packet requires more processing power than most general purpose processor can provide. Thus, researchers have developed high performance parallel deep packet filters for reconfigurable devices. Although some reconfigurable systems can be generated automatically from pattern database, obtaining high performance result from each subsequent reconfiguration can be a time consuming process. We present a novel architecture for programmable parallel pattern matching coprocessor. By combining a scalable co-processor with the compact reconfigurable filter, we produce a hybrid system that is able to update the rules immediate during the time the new filter is being compiled. We mapped our hybrid filter for the latest Snort rule set on January 13, 2005, containing 2,044 unique patterns byte make up 32,384 bytes, onto a single Xilinx Virtex 4LX - XC4VLX15 FPGA with a filtering rate of 2 Gbps.
Citation:
Young H. Cho, William H. Mangione-Smith, "Fast Reconfiguring Deep Packet Filter for 1+ Gigabit Network," fccm, pp.215-224, 13th Annual IEEE Symposium on Field-Programmable Custom Computing Machines (FCCM'05), 2005
Usage of this product signifies your acceptance of the Terms of Use.