The NADIA: A Network Acceleration System with Defense against Network Invasion and Attack

  • Kim, Sunwook
  • Kim, Byunggu
  • Kim, Seongwoon
  • Park, Jinwon
  • Chung, Yongwha
Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Information security plays a critical role in the design of high-speed network systems, and much attention is focused on the Network Intrusion Prevention System (NIPS) which combines both a firewall and a Network Intrusion Detection System (NIDS). However, the current generation of NIDS/NIPS has several limitations on performance and effectiveness. In this paper, we describe the Network Accelerator with Defense against Invasion and Attack (NADIA) architecture as a network security card. The NADIA system consists of NADIA hardware for network and security processing and NADIA software for a device driver and a management agent. The goal of the network acceleration hardware is to reduce the overhead of the host CPU for network processing. And, the security function hardware performs operations such as network ACL, DPI, DDoS blocking, and session control, in order to check whether the received packets are malicious or not. Based on the performance evaluation, we can confirm that NADIA can reduce the CPU overhead of the network and security processing by a factor of 5 similar to 14.

키워드

DDoSGigabitHome networkNetwork offloadingNetwork intrusion detection systemNetwork intrusion prevention systemSnort ruleTCPIP overhead
제목
The NADIA: A Network Acceleration System with Defense against Network Invasion and Attack
저자
Kim, SunwookKim, ByungguKim, SeongwoonPark, JinwonChung, Yongwha
DOI
10.4103/0377-2063.104158
발행일
2012-09
유형
Article
저널명
IETE Journal of Research
58
5
페이지
398 ~ 410