博碩士論文 974203046 完整後設資料紀錄

DC 欄位 語言
DC.contributor資訊管理學系zh_TW
DC.creator朱彥豪zh_TW
DC.creatorYan-Hao Chuen_US
dc.date.accessioned2010-7-21T07:39:07Z
dc.date.available2010-7-21T07:39:07Z
dc.date.issued2010
dc.identifier.urihttp://ir.lib.ncu.edu.tw:88/thesis/view_etd.asp?URN=974203046
dc.contributor.department資訊管理學系zh_TW
DC.description國立中央大學zh_TW
DC.descriptionNational Central Universityen_US
dc.description.abstract隨著網際網路的蓬勃發展,在網路上的應用也日益增多,相對的網路安全問題也隨著網路的普及越來越受到重視,基於特徵比對之網路型入侵偵測系統便成為不可或缺的基礎防護。然而目前網路型入侵偵測系統大多實作於軟體之上,相對於網路進入高速傳輸的今日已不敷使用,且酬載內容比對相較於標頭比對需要較多的計算量,也成為軟體比對的瓶頸。本研究以史丹佛大學與Xilinx合作開發的NetFPGA平台設計網路惡意封包偵測器以達到快速比對效果,雖然在FPGA上設計之IC具有快速、平行比對、與快速雛型化之特性,但該平台所能使用的資源有限,而特徵資料庫需要不斷的更新以達到比對成效,故本研究以決策樹檢測封包之標頭節省電路資源消耗,再依標頭比對之架構建置多字串比對群組來進行封包酬載之比對,並且在每個字串群組以布隆過濾器濾掉沒有惡意嫌疑的酬載內容,並以改良式Karp-Rabin演算法降低布隆過濾器存有之誤報率且達到多比對之效果,本研究經由實驗證明此設計的確可以較少的資源利用達到快速且有效之比對結果。 zh_TW
dc.description.abstractAlso day by day increases along with Internet’’s rapid development in network’’s application, the relative network security problem also more and more receives along with network’’s popularization takes seriously, compared to then becomes the indispensable foundation protection based on the characteristic to it network intrusion detector. However present network intrusion detector is mostly solid does above the software, is opposite enters high speed transmission in the network today to use insufficiently, and the payload content need more computation loads, it also becomes the software compares to the bottleneck. This research using FPGA platform design network intrusion detector achieves by the Standford University and Xilinx cooperate development’’s NetFPGA fast compared to the effect, although IC of design has fast on FPGA , but this platform can use the resources are limited, therefore this research saves the resources consumption by decision tree examine header, depends on it to establish the multi-strings group again to it construction to carry on ratio of the payload to the group to be more right than, and filters out the payload in each string groups by the Bloom Filter which does not have suspicion, and the improvement Karp-Rabin Algorithm calculating method reduces the Bloom Filter to have the rate of false alarm, and achieves multi-matching to it effect, this research by way of the experiment proved that this design indeed may the few resources use achieve fast and the effective ratio to the result. en_US
DC.subjectNetFPGAzh_TW
DC.subject布隆過濾器zh_TW
DC.subject入侵偵測系統zh_TW
DC.subject改良式Karp-Rabin演算法zh_TW
DC.subjectIntrusion Detectionen_US
DC.subjectNetFPGAen_US
DC.subjectModified Karp Rabin Algorithmen_US
DC.subjectBloom Filteren_US
DC.title以NetFPGA實作結合布隆過濾器與改良式Karp Rabin演算法之網路惡意封包偵測器zh_TW
dc.language.isozh-TWzh-TW
DC.titleUsing NetFPGA to Implement Bloom Filter And Modified Karp Rabin Algorithm Based Network Intrusion Detectoren_US
DC.type博碩士論文zh_TW
DC.typethesisen_US
DC.publisherNational Central Universityen_US

若有論文相關問題,請聯絡國立中央大學圖書館推廣服務組 TEL:(03)422-7151轉57407,或E-mail聯絡  - 隱私權政策聲明