09.08.2013 Views

FPGA Based Network Security architecture for High Speed Networks

FPGA Based Network Security architecture for High Speed Networks

FPGA Based Network Security architecture for High Speed Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 5<br />

<strong>FPGA</strong> based string matching <strong>for</strong><br />

<strong>Network</strong> Intrusion Detection<br />

System<br />

5.1 Introduction<br />

The field of network security guarantees the prevention and monitoring of unautho-<br />

rized access, misuse, modification as well as denial of network accessible resources.<br />

The major goals of network security includes confidentiality, data integrity, au-<br />

thentication and non repudiation. In the same context, intrusion detection is a<br />

security management tool which monitors network traffic <strong>for</strong> detecting possible<br />

security breaches. These security breaches attempt to compromise the confiden-<br />

tiality, integrity or availability of network resources and can be either from out-<br />

side or inside the network concerned. In traditional networks, firewalls are used<br />

to monitor and filter incoming and outgoing packets but they cannot eliminate<br />

all security threats, nor they can detect attacks when they happen. It is like a<br />

locked gate to a treasure house that prevent the entry of thieves. <strong>Network</strong> Intru-<br />

sion Detection System (NIDS) is another network processing application, which is<br />

either a software application (example Snort) or a hardware device that monitors<br />

network <strong>for</strong> malicious activities such as denial of service attacks, port scans etc.<br />

This NIDS along with <strong>Network</strong> Intrusion Prevention System (NIPS) are essen-<br />

tial network security appliances that helps in maintaining the security goals in a<br />

network to a great extent. Intrusion Detection and Prevention Systems (IDPS)<br />

39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!