发明申请
- 专利标题: Intrusion detection using a network processor and a parallel pattern detection engine
- 专利标题(中): 使用网络处理器和并行模式检测引擎的入侵检测
-
申请号: US10756904申请日: 2004-01-14
-
公开(公告)号: US20050154916A1公开(公告)日: 2005-07-14
- 发明人: Marc Boulanger , Clark Jeffries , C. Kinard , Kerry Kravec , Ravinder Sabhikhi , Ali Saidi , Jan Slyfield , Pascal Tannhof
- 申请人: Marc Boulanger , Clark Jeffries , C. Kinard , Kerry Kravec , Ravinder Sabhikhi , Ali Saidi , Jan Slyfield , Pascal Tannhof
- 申请人地址: US NY Armonk
- 专利权人: International Business Machine Corporation
- 当前专利权人: International Business Machine Corporation
- 当前专利权人地址: US NY Armonk
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; H04L12/24 ; H04L29/06
摘要:
An intrusion detection system (IDS) comprises a network processor (NP) coupled to a memory unit for storing programs and data. The NP is also coupled to one or more parallel pattern detection engines (PPDE) which provide high speed parallel detection of patterns in an input data stream. Each PPDE comprises many processing units (PUs) each designed to store intrusion signatures as a sequence of data with selected operation codes. The PUs have configuration registers for selecting modes of pattern recognition. Each PU compares a byte at each clock cycle. If a sequence of bytes from the input pattern match a stored pattern, the identification of the PU detecting the pattern is outputted with any applicable comparison data. By storing intrusion signatures in many parallel PUs, the IDS can process network data at the NP processing speed. PUs may be cascaded to increase intrusion coverage or to detect long intrusion signatures.
公开/授权文献
信息查询