Dissertation > Excellent graduate degree dissertation topics show
Intrusion prevention system based on multi-core research
Author: YangWei
Tutor: Liu
School: University of Electronic Science and Technology
Course: Computer System Architecture
Keywords: Intrusion Prevention Multi-core Processor Affinity Parallel Detection Memory Map
CLC: TP393.08
Type: Master's thesis
Year: 2009
Downloads: 166
Quote: 2
Read: Download Dissertation
Abstract
|
As the application of the computer and network technology is popularized more and more, various kinds of network security issues have become increasingly obvious. Lots of security technologies and systems are developed to solve specific security issues. As the traditional network security technologies, both Firewall and Intrusion Detection System (IDS) have their own defects, they can’t solve the increasingly serious network security problem.Firstly, the implementation principles and defects of Firewall and Intrusion Detection System are introduced and analyzed in this thesis, and then the concept of Intrusion Prevention System (IPS) is introduced. IPS is one of the network security technologies in recent years. Due to IPS is deployed in the network with online mode, its performance will affect the whole operating efficiency across the network. The implementation of Intrusion Prevention System based on Multi-core processor hardware platform is proposed in this thesis, using the multi-core parallel technology to solve the current performance problem of Intrusion Prevention System.Secondly, the hardware and software architecture design of the system is introduced in this thesis. This project takes XLR732 multi-core processor which is produced by RMI as its hardware platform, and takes Topsec TOS network security operating system as its software platform. Then some import modules of the system are introduced, and the key problems are analyzed in this thesis. It mainly gives a detailed description of the following several modules:1) Packet Receiving and Sending module is the bridge of data packet interaction between the kernel space and the user space detection process. It allocates some memory in kernel to constitute several circular queues, and maps the memory into the user space. This zero-copy method can accelerate the efficiency of the user space to access the data packet.2) Fast Detection module is a pre-filtering for packet processing. It decides whether the packet is necessary to be sent to the user space according to its source and destination port. The number of packets which be sent to the user space decreased, so the performance of the system can be improved.3) Parallel Detection module starts several detection processes in the user space, and separately be bound to different processors to parallel run. Each detection process fetches the packet from the mapped circular queue and then matches the content of the packet. At the end of the detection, it sends the detection results to the kernel through the packet receiving and sending module.Finally, some functional testing and performance testing on the system have been done in this thesis, and an evaluation of the test results has been worked out. All these test results verify the correction of the system design.
|
Related Dissertations
- Implementation and Research on Radio Link Control Protocol in TD-SCDMA,TN929.533
- The Research on A Scheduling Algorithm for Real-time Tasks in Multi-core Systems,TP332
- The Research on Online Adaptive Settings,TM77
- Study of snort -based IPS,TP393.08
- Platform for ATM host intrusion defense systems design and implementation,TP393.08
- Research on Parallel and Distributed Intrusion Detection Technologies,TP393.08
- Research on Intrusion Protective Mechanism of Database Based on User Behavior Mining,TP311.13
- Fault-Tolerant Routing Algorithms for 2D-MESH Based Network-on-Chip,TP302.8
- The embedded MSDCC heterogeneous multicore compiler research,TP314
- Study on Key Technologies of Realizing an Intelligent Intrusion Prevention System,TP393.08
- Intrusion Prevention System of Campus Network,TP393.18
- Research and Design of an IPS-based Detection Engine,TP393.08
- Design and Implementation of Parallel Image Matching Algorithm Based on MDSP,TP391.41
- Research of Multi-core Program Optimization Based on Task Parallel Strategies,TP332
- Research and Implementation of Behavior-based Host Intrusion Prevention System,TP393.08
- Research on Network Intrusion Prevention System Based on Snort,TP393.08
- Study on Parallel Detection Related Technology Based on Piezoelectric Micro-cantilevers Array,TH742
- Windows Native API calls for intrusion prevention technology research,TP393.08
- The Application of IPS on the Campus,TP393.18
- Based on protocol analysis Intrusion Prevention System Research and Implementation,TP393.08
- Key Management for Wireless Sensor Network Detection and Intrusion Prevention,TP212.9
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net Mobile
|