论文部分内容阅读
网络的高速发展给人们的生活带来了便利,但网络入侵等非法应用妨碍了互联网的正常使用,高效的规则处理系统可以保护网络免受攻击。文中针对当前各种规则匹配算法处理速度慢,无法满足高速网安全应用的需求,提出了一种基于硬件的规则匹配算法。该算法通过向量运算完成规则匹配,并使用硬件并行处理,大大提高了规则匹配的匹配速度。设计并实现了一个基于该算法的硬件匹配单元,并通过实验验证该算法完全可以满足高速网络中入侵检测等数据处理要求。
The rapid development of the Internet has brought convenience to people’s lives. However, illegal applications such as network intrusion prevent the normal use of the Internet and an efficient system of rules processing can protect the network from attacks. In this paper, we present a hardware-based rule matching algorithm for the current rules matching algorithm to process slowly and can not meet the needs of high-speed network security applications. The algorithm completes rule matching through vector operations and uses hardware parallel processing, which greatly improves the matching speed of rule matching. A hardware matching unit based on the algorithm is designed and implemented. The algorithm is verified by experiments that the algorithm can meet the data processing requirements such as intrusion detection in high-speed networks.