Snort offloader: A reconfigurable hardware NIDS filter

  • Haoyu Song
  • , Todd Sproull
  • , Mike Attig
  • , John Lockwood

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Software-based Network Intrusion Detection Systems (NIDS) often fail to keep up with high-speed network links. In this paper an FPGA-based pre-filter is presented that reduces the amount of traffic sent to a software-based NIDS for inspection. Simulations using real network traces and the Snort rule set show that a pre-filter can reduce up to 90% of network traffic that would have otherwise been processed by Snort software. The projected performance enables a computer to perform real-time intrusion detection of malicious content passing over a 10Gbps network using FPGA hardware that operates with 10 Gbps of throughput and software that needs only to operate with 1 Gbps of throughput.

Original languageEnglish
Title of host publicationProceedings - 2005 International Conference on Field Programmable Logic and Applications, FPL
Pages493-498
Number of pages6
StatePublished - 2005
Event2005 International Conference on Field Programmable Logic and Applications, FPL - Tampere, Finland
Duration: Aug 24 2005Aug 26 2005

Publication series

NameProceedings - 2005 International Conference on Field Programmable Logic and Applications, FPL
Volume2005

Conference

Conference2005 International Conference on Field Programmable Logic and Applications, FPL
Country/TerritoryFinland
CityTampere
Period08/24/0508/26/05

Fingerprint

Dive into the research topics of 'Snort offloader: A reconfigurable hardware NIDS filter'. Together they form a unique fingerprint.

Cite this