語系:
繁體中文
English
說明(常見問題)
回圖書館首頁
手機版館藏查詢
登入
回首頁
切換:
標籤
|
MARC模式
|
ISBD
Packet content inspection: Repetitio...
~
Faezipour, Miad.
FindBook
Google Book
Amazon
博客來
Packet content inspection: Repetition-based methodologies and hardware implementation.
紀錄類型:
書目-語言資料,印刷品 : Monograph/item
正題名/作者:
Packet content inspection: Repetition-based methodologies and hardware implementation./
作者:
Faezipour, Miad.
面頁冊數:
165 p.
附註:
Source: Dissertation Abstracts International, Volume: 71-08, Section: B, page: 5013.
Contained By:
Dissertation Abstracts International71-08B.
標題:
Engineering, Computer. -
電子資源:
http://pqdd.sinica.edu.tw/twdaoapp/servlet/advanced?query=3414903
ISBN:
9781124096629
Packet content inspection: Repetition-based methodologies and hardware implementation.
Faezipour, Miad.
Packet content inspection: Repetition-based methodologies and hardware implementation.
- 165 p.
Source: Dissertation Abstracts International, Volume: 71-08, Section: B, page: 5013.
Thesis (Ph.D.)--The University of Texas at Dallas, 2010.
Today's network intrusion detection systems (NIDS) are expected to thoroughly analyze packet contents to identify any traces of suspicious activities such as worms or viruses. Internet threats are either completely new and unknown, or previously known. In the former, we deal with identifying worm outbreaks never seen before, while the latter deals with scanning data packets to find traces of previously known or pre-defined worm signatures. In this dissertation, both cases are addressed. The main contribution of our work is twofold. First, we look for frequently repeated strings in a packet stream to detect worm outbreaks. A novel real-time worm outbreak detection system using two-phase hashing is proposed. We use the concept of shared counters to minimize the memory cost while efficiently sifting through packet contents to find suspicious strings. We have implemented our system on reconfigurable hardware and have tested it for various settings and packet stream sizes. Experimental results verify that our system can support line speed of gigabit-rates with negligible false positive and false negative. Second, we investigate a more efficient implementation of NIDS rules using regular expressions that represent suspicious or malicious character sequences in packet payloads. We introduce a new building block based on Non-deterministic Finite Automata (NFA) hardware implementation to support complex constraint repetitions in regular expressions. We report results of hardware implementation that verify the overall performance. In the final part of this dissertation, we investigate practical applications of the proposed algorithms, mainly biomedical signal classification and various networking applications that require some abnormality/irregularity detection.
ISBN: 9781124096629Subjects--Topical Terms:
1669061
Engineering, Computer.
Packet content inspection: Repetition-based methodologies and hardware implementation.
LDR
:02990nam 2200289 4500
001
1401273
005
20111017083859.5
008
130515s2010 ||||||||||||||||| ||eng d
020
$a
9781124096629
035
$a
(UMI)AAI3414903
035
$a
AAI3414903
040
$a
UMI
$c
UMI
100
1
$a
Faezipour, Miad.
$3
1680398
245
1 0
$a
Packet content inspection: Repetition-based methodologies and hardware implementation.
300
$a
165 p.
500
$a
Source: Dissertation Abstracts International, Volume: 71-08, Section: B, page: 5013.
500
$a
Adviser: Mehrdad Nourani.
502
$a
Thesis (Ph.D.)--The University of Texas at Dallas, 2010.
520
$a
Today's network intrusion detection systems (NIDS) are expected to thoroughly analyze packet contents to identify any traces of suspicious activities such as worms or viruses. Internet threats are either completely new and unknown, or previously known. In the former, we deal with identifying worm outbreaks never seen before, while the latter deals with scanning data packets to find traces of previously known or pre-defined worm signatures. In this dissertation, both cases are addressed. The main contribution of our work is twofold. First, we look for frequently repeated strings in a packet stream to detect worm outbreaks. A novel real-time worm outbreak detection system using two-phase hashing is proposed. We use the concept of shared counters to minimize the memory cost while efficiently sifting through packet contents to find suspicious strings. We have implemented our system on reconfigurable hardware and have tested it for various settings and packet stream sizes. Experimental results verify that our system can support line speed of gigabit-rates with negligible false positive and false negative. Second, we investigate a more efficient implementation of NIDS rules using regular expressions that represent suspicious or malicious character sequences in packet payloads. We introduce a new building block based on Non-deterministic Finite Automata (NFA) hardware implementation to support complex constraint repetitions in regular expressions. We report results of hardware implementation that verify the overall performance. In the final part of this dissertation, we investigate practical applications of the proposed algorithms, mainly biomedical signal classification and various networking applications that require some abnormality/irregularity detection.
520
$a
Keywords: Network intrusion detection system, repeated strings, hashing, shared counters, false positive, false negative, worm outbreak, non-deterministic finite automata, regular expression, constraint repetition inspection, vehicle-area-networks, biomedical signal classification.
590
$a
School code: 0382.
650
4
$a
Engineering, Computer.
$3
1669061
650
4
$a
Engineering, Electronics and Electrical.
$3
626636
690
$a
0464
690
$a
0544
710
2
$a
The University of Texas at Dallas.
$3
1018411
773
0
$t
Dissertation Abstracts International
$g
71-08B.
790
1 0
$a
Nourani, Mehrdad,
$e
advisor
790
$a
0382
791
$a
Ph.D.
792
$a
2010
856
4 0
$u
http://pqdd.sinica.edu.tw/twdaoapp/servlet/advanced?query=3414903
筆 0 讀者評論
館藏地:
全部
電子資源
出版年:
卷號:
館藏
1 筆 • 頁數 1 •
1
條碼號
典藏地名稱
館藏流通類別
資料類型
索書號
使用類型
借閱狀態
預約狀態
備註欄
附件
W9164412
電子資源
11.線上閱覽_V
電子書
EB
一般使用(Normal)
在架
0
1 筆 • 頁數 1 •
1
多媒體
評論
新增評論
分享你的心得
Export
取書館
處理中
...
變更密碼
登入