论文部分内容阅读
入侵检测技术是维护网络安全的一种重要手段。为了克服现有入侵检测系统在处理速度上的不足,该文提出了一种基于网络处理器和处理机群的高速入侵检测系统结构。重点讨论如何采用网络处理器实现系统中的流量分配器。对网络处理器的多线程数据采集、流量分配两个算法作了详细的分析。研究结果表明,经过算法优化,采用网络处理器IXP 1200实现的流量分配器可以完成1 G b.-s 1以上数据的实时采集,基于目的媒体接入控制(M AC)地址的转发策略在维护信息完整性和降低处理复杂度两方面体现了很好的折中,达到了合理的流量分配。
Intrusion detection technology is an important means of maintaining network security. In order to overcome the shortcomings of existing intrusion detection system in processing speed, this paper proposes a high-speed intrusion detection system based on network processor and processor cluster. Focus on how to use network processors to achieve the system traffic distributor. Network processor multi-threaded data acquisition, traffic distribution of two algorithms made a detailed analysis. The results show that, after optimization, the traffic allocator with network processor IXP 1200 can accomplish the real-time data acquisition of more than 1 G b.-s 1. The forwarding strategy based on destination MAC address Information integrity and reduce processing complexity reflects a good compromise between the two, to achieve a reasonable allocation of traffic.